Uncontrolled Search Path Vulnerability in NVIDIA GeForce Experience Installers
CVE-2022-31611
6.8MEDIUM
Summary
NVIDIA GeForce Experience is affected by an uncontrolled search path vulnerability in its client installers. This issue allows an attacker with user-level privileges to manipulate the installer, potentially causing it to load an arbitrary Dynamic Link Library (DLL) upon launch. Should the exploit be successful, it may result in privilege escalation and unauthorized code execution, posing serious risks to users' systems and data security.
Affected Version(s)
GeForce Experience Windows All versions prior to 3.27.0.112
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved