NVIDIA GPU Display Driver Vulnerability Allowing Unprivileged User Access to Sensitive Data
CVE-2024-0107

7.8HIGH

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
8 August 2024

Summary

The NVIDIA GPU Display Driver for Windows features a vulnerability in its user mode layer that enables an unprivileged regular user to execute an out-of-bounds read. Exploitation of this flaw can lead to significant security risks, including unauthorized code execution, service interruptions, an escalation of privileges, potential information disclosure, and the capability for data manipulation. Users and administrators utilizing the affected product should take immediate action to mitigate these risks.

Affected Version(s)

GPU Display Driver, vGPU Software, Cloud Gaming Windows All versions up to and including the June 2024 release

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.