Lucene search

K
ibmIBM184451CF1AACF7004AC2F658076A91BF6C7A7735E303D9906A64A678F2BD9A1C
HistoryApr 27, 2020 - 10:08 p.m.

Security Bulletin: NVIDIA Windows and Linux GPU Display drivers are have resolved several security vulnerabilities as described below.

2020-04-2722:08:49
www.ibm.com
15

EPSS

0.001

Percentile

20.2%

Summary

The NVIDIA Windows and Linux GPU Display drivers have resolved several ecurity vulnerabilities as described by the following CVEs:

Vulnerability Details

CVEID:CVE-2019-5690
**DESCRIPTION:**NVIDIA Windows GPU Display driver could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper buffer validation in nvlddmkm.sys for DxgkDdiEscape. An attacker could exploit this vulnerability gain higher privileges on the system.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171256 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-5691
**DESCRIPTION:**NVIDIA Windows GPU Display driver could allow a local authenticated attacker to gain elevated privileges on the system, caused by a NULL pointer dereference in nvlddmkm.sys for DxgkDdiEscape. An attacker could exploit this vulnerability to gain higher privileges on the system.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171257 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-5692
**DESCRIPTION:**NVIDIA Windows GPU Display driver could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper input validation in nvlddmkm.sys for DxgkDdiEscape. An attacker could exploit this vulnerability to gain higher privileges on the system.
CVSS Base score: 7.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171258 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)

CVEID:CVE-2019-5693
**DESCRIPTION:**Nvidia Windows GPU Display Driver is vulnerable to a denial of service, caused by improper use of an uninitialized pointer by nvlddmkm.sys. A local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171259 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)

CVEID:CVE-2019-5694
**DESCRIPTION:**NVIDIA Control Panel could allow a local authenticated attacker to execute arbitrary code on the system, caused by improper validation of system DLLs. By creating specially-drafted input, an attacker could exploit this vulnerability to execute arbitrary code execution on the system.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171260 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-5695
**DESCRIPTION:**NVIDIA GeForce Experience and Windows GPU Display driver could allow a local authenticated attacker to execute arbitrary code on the system, caused by improper validation of system DLLs. An attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171252 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-5696
**DESCRIPTION:**Nvidia Virtual GPU Manager is vulnerable to a denial of service, caused by improper bounds checking by a guest VM. A local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171261 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2019-5697
**DESCRIPTION:**NVIDIA Virtual GPU Manager is vulnerable to a denial of service, caused by improper handling of memory allocation. A local authenticated attacker could exploit this vulnerability to cause a denial of service condition or possibly disclose sensitive information.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171262 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-5698
**DESCRIPTION:**Nvidia Windows GPU Display Driver is vulnerable to a denial of service. A local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171263 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
NVIDIA GPU Display Driver for Linux 410.104
NVIDIA GPU Display Driver for Windows 412.29

Remediation/Fixes

Affected Product(s)

|

Version(s)

—|—

NVIDIA GPU Display Driver for Windows

(nvda_dd_video_441.22_windows_x86-64)

(nvda_dd_video_441.22_win2016_x86-64)

|

441.22

NVIDIA GPU Display Driver for Linux

(nvda_dd_video_440.33.01_linux_x86-64)

|

440.33.01

Workarounds and Mitigations

None

EPSS

0.001

Percentile

20.2%

Related for 184451CF1AACF7004AC2F658076A91BF6C7A7735E303D9906A64A678F2BD9A1C