NVIDIA GPU Display Driver Vulnerability Allowing Unprivileged User Access to Sensitive Data
CVE-2024-0107

7.8HIGH

What is CVE-2024-0107?

The NVIDIA GPU Display Driver for Windows features a vulnerability in its user mode layer that enables an unprivileged regular user to execute an out-of-bounds read. Exploitation of this flaw can lead to significant security risks, including unauthorized code execution, service interruptions, an escalation of privileges, potential information disclosure, and the capability for data manipulation. Users and administrators utilizing the affected product should take immediate action to mitigate these risks.

Affected Version(s)

GPU Display Driver, vGPU Software, Cloud Gaming Windows All versions up to and including the June 2024 release

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-0107 : NVIDIA GPU Display Driver Vulnerability Allowing Unprivileged User Access to Sensitive Data