Lucene search

K
cveNvidiaCVE-2020-5964
HistoryJun 25, 2020 - 12:15 a.m.

CVE-2020-5964

2020-06-2500:15:10
CWE-345
nvidia
web.nvd.nist.gov
46
nvidia
windows
gpu
display driver
vulnerability
service host
code execution
denial of service
information disclosure
cve-2020-5964

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

12.6%

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.

Affected configurations

Nvd
Node
nvidiaquadro_firmwareRange390392.61
OR
nvidiaquadro_firmwareRange418426.78
OR
nvidiaquadro_firmwareRange440443.18
OR
nvidiaquadro_firmwareRange450451.48
AND
nvidiaquadroMatch-
Node
nvidiatesla_firmwareRange418426.78
OR
nvidiatesla_firmwareRange440443.18
OR
nvidiatesla_firmwareRange450451.48
AND
nvidiateslaMatch-
Node
nvidiageforce_experienceRange<3.20.4
AND
microsoftwindowsMatch-
Node
nvidianvs_firmwareRange390392.61
OR
nvidianvs_firmwareRange418426.78
OR
nvidianvs_firmwareRange440443.18
OR
nvidianvs_firmwareRange450451.48
AND
nvidianvsMatch-
Node
nvidiageforce_firmwareRange450451.48
AND
nvidiageforceMatch-
VendorProductVersionCPE
nvidiaquadro_firmware*cpe:2.3:o:nvidia:quadro_firmware:*:*:*:*:*:*:*:*
nvidiaquadro-cpe:2.3:h:nvidia:quadro:-:*:*:*:*:*:*:*
nvidiatesla_firmware*cpe:2.3:o:nvidia:tesla_firmware:*:*:*:*:*:*:*:*
nvidiatesla-cpe:2.3:h:nvidia:tesla:-:*:*:*:*:*:*:*
nvidiageforce_experience*cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
nvidianvs_firmware*cpe:2.3:o:nvidia:nvs_firmware:*:*:*:*:*:*:*:*
nvidianvs-cpe:2.3:h:nvidia:nvs:-:*:*:*:*:*:*:*
nvidiageforce_firmware*cpe:2.3:o:nvidia:geforce_firmware:*:*:*:*:*:*:*:*
nvidiageforce-cpe:2.3:h:nvidia:geforce:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "NVIDIA GPU Display Driver",
    "vendor": "NVIDIA",
    "versions": [
      {
        "status": "affected",
        "version": "All"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

12.6%