Uncontrolled Search Path Vulnerability in NVIDIA GeForce Experience Installers
CVE-2022-31611

6.8MEDIUM

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
7 February 2023

Summary

NVIDIA GeForce Experience is affected by an uncontrolled search path vulnerability in its client installers. This issue allows an attacker with user-level privileges to manipulate the installer, potentially causing it to load an arbitrary Dynamic Link Library (DLL) upon launch. Should the exploit be successful, it may result in privilege escalation and unauthorized code execution, posing serious risks to users' systems and data security.

Affected Version(s)

GeForce Experience Windows All versions prior to 3.27.0.112

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.