Buffer Overrun Vulnerability in NVIDIA vGPU Software
CVE-2022-42262

7.1HIGH

Key Information:

Summary

NVIDIA vGPU software includes a buffer overrun vulnerability in the Virtual GPU Manager plugin. This issue arises from improper validation of an input index, which can be exploited to cause data tampering, disclose sensitive information, or potentially lead to service disruptions.

Affected Version(s)

vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.