CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
20.8%
For the NVIDIA Quadro, NVS, and GeForce products, the NVIDIA NVStreamKMS.sys service component is improperly validating user-supplied data through its API entry points causing an elevation of privilege.
Vendor | Product | Version | CPE |
---|---|---|---|
nvidia | geforce_experience | - | cpe:2.3:a:nvidia:geforce_experience:-:*:*:*:*:*:*:* |
nvidia | geforce_910m | - | cpe:2.3:h:nvidia:geforce_910m:-:*:*:*:*:*:*:* |
nvidia | geforce_920m | - | cpe:2.3:h:nvidia:geforce_920m:-:*:*:*:*:*:*:* |
nvidia | geforce_920mx | - | cpe:2.3:h:nvidia:geforce_920mx:-:*:*:*:*:*:*:* |
nvidia | geforce_930m | - | cpe:2.3:h:nvidia:geforce_930m:-:*:*:*:*:*:*:* |
nvidia | geforce_930mx | - | cpe:2.3:h:nvidia:geforce_930mx:-:*:*:*:*:*:*:* |
nvidia | geforce_940m | - | cpe:2.3:h:nvidia:geforce_940m:-:*:*:*:*:*:*:* |
nvidia | geforce_940mx | - | cpe:2.3:h:nvidia:geforce_940mx:-:*:*:*:*:*:*:* |
nvidia | geforce_945m | - | cpe:2.3:h:nvidia:geforce_945m:-:*:*:*:*:*:*:* |
nvidia | geforce_gt_710 | - | cpe:2.3:h:nvidia:geforce_gt_710:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
20.8%