Lucene search

K
ibmIBM68F0A4AD202F94F0577EFDEB722285075D55E51ED6D10E519709AD743B125CE8
HistoryJun 25, 2020 - 6:26 p.m.

Security Bulletin: NVIDIA Windows GPU Display driver is vulnerable to several security vulnerabilities.

2020-06-2518:26:00
www.ibm.com
9

0.001 Low

EPSS

Percentile

36.7%

Summary

The NVIDIA Windows GPU Display driver is vulnerable to several security vulnerabilities as described by the following CVEs:

Vulnerability Details

CVEID:CVE-2019-5677
**DESCRIPTION:**NVIDIA Windows GPU Display driver is vulnerable to a denial of service, caused by a flaw in the kernel mode layer (nvlddmkm.sys) handler for DeviceIoControl. A local authenticated attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 5.6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/161195 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H)

CVEID:CVE-2019-5676
**DESCRIPTION:**NVIDIA Windows GPU Display driver could allow a local authenticated attacker to execute arbitrary code on the system, caused by the loading of dynamic-linked libraries in an insecure manner. By placing a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code and escalate privileges on the system.
CVSS Base score: 7.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/161196 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H)

CVEID:CVE-2019-5675
**DESCRIPTION:**NVIDIA Windows GPU Display driver could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape. An attacker could exploit this vulnerability to cause denial of service, escalation of privileges, or information disclosure.
CVSS Base score: 7.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/161197 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
NVIDIA GPU Display Driver for Windows 412.29

Remediation/Fixes

Affected Product(s)

|

Version(s)

—|—

NVIDIA GPU Display Driver for Windows

(nvda_dd_video_441.22_windows_x86-64)

(nvda_dd_video_441.22_win2016_x86-64)

|

441.22

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

36.7%

Related for 68F0A4AD202F94F0577EFDEB722285075D55E51ED6D10E519709AD743B125CE8