Lucene search

K
cve[email protected]CVE-2016-4960
HistoryNov 08, 2016 - 8:59 p.m.

CVE-2016-4960

2016-11-0820:59:02
CWE-20
web.nvd.nist.gov
23
nvidia
nvstreamkms
cve-2016-4960
security
privilege escalation

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.3 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.0%

For the NVIDIA Quadro, NVS, and GeForce products, the NVIDIA NVStreamKMS.sys service component is improperly validating user-supplied data through its API entry points causing an elevation of privilege.

Affected configurations

NVD
Node
nvidiageforce_experienceMatch-
AND
nvidiageforce_910mMatch-
OR
nvidiageforce_920mMatch-
OR
nvidiageforce_920mxMatch-
OR
nvidiageforce_930mMatch-
OR
nvidiageforce_930mxMatch-
OR
nvidiageforce_940mMatch-
OR
nvidiageforce_940mxMatch-
OR
nvidiageforce_945mMatch-
OR
nvidiageforce_gt_710Match-
OR
nvidiageforce_gt_730Match-
OR
nvidiageforce_gtx_1050Match-
OR
nvidiageforce_gtx_1060Match-
OR
nvidiageforce_gtx_1070Match-
OR
nvidiageforce_gtx_1080Match-
OR
nvidiageforce_gtx_950mMatch-
OR
nvidiageforce_gtx_960mMatch-
OR
nvidiageforce_gtx_965mMatch-
OR
nvidianvs_310Match-
OR
nvidianvs_315Match-
OR
nvidianvs_510Match-
OR
nvidianvs_810Match-
OR
nvidiaquadro_k1200Match-
OR
nvidiaquadro_k420Match-
OR
nvidiaquadro_k620Match-
OR
nvidiaquadro_m1000mMatch-
OR
nvidiaquadro_m2000Match-
OR
nvidiaquadro_m2000mMatch-
OR
nvidiaquadro_m3000mMatch-
OR
nvidiaquadro_m4000Match-
OR
nvidiaquadro_m4000mMatch-
OR
nvidiaquadro_m5000Match-
OR
nvidiaquadro_m5000mMatch-
OR
nvidiaquadro_m500mMatch-
OR
nvidiaquadro_m5500Match-
OR
nvidiaquadro_m6000Match-
OR
nvidiaquadro_m600mMatch-
OR
nvidiaquadro_p5000Match-
OR
nvidiaquadro_p6000Match-
OR
nvidiatitan_xMatch-

CNA Affected

[
  {
    "product": "Quadro, NVS, GeForce (all versions)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Quadro, NVS, GeForce (all versions)"
      }
    ]
  }
]

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.3 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.0%