Uncontrolled Search Path Vulnerability in NVIDIA GeForce Experience Installers
CVE-2022-31611

6.8MEDIUM

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
7 February 2023

What is CVE-2022-31611?

NVIDIA GeForce Experience is affected by an uncontrolled search path vulnerability in its client installers. This issue allows an attacker with user-level privileges to manipulate the installer, potentially causing it to load an arbitrary Dynamic Link Library (DLL) upon launch. Should the exploit be successful, it may result in privilege escalation and unauthorized code execution, posing serious risks to users' systems and data security.

Affected Version(s)

GeForce Experience Windows All versions prior to 3.27.0.112

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.