Buffer Overrun Vulnerability in NVIDIA vGPU Software
CVE-2022-42262
7.1HIGH
Key Information:
- Vendor
- Nvidia
- Vendor
- CVE Published:
- 30 December 2022
Summary
NVIDIA vGPU software includes a buffer overrun vulnerability in the Virtual GPU Manager plugin. This issue arises from improper validation of an input index, which can be exploited to cause data tampering, disclose sensitive information, or potentially lead to service disruptions.
Affected Version(s)
vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved