Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-0073
HistoryMar 27, 2024 - 12:00 a.m.

CVE-2024-0073

2024-03-2700:00:00
ubuntu.com
ubuntu.com
10
nvidia gpu display driver
windows
privilege escalation
code execution
dos
data tampering

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

NVIDIA GPU Display Driver for Windows contains a vulnerability in the
kernel mode layer when the driver is performing an operation at a privilege
level that is higher than the minimum level required. A successful exploit
of this vulnerability may lead to code execution, denial of service,
escalation of privileges, information disclosure, and data tampering.

Notes

Author Note
mdeslaur some binary drivers are no longer support by NVidia, so they are marked as ignored here
rodrigo-zaiden affects Windows drivers only.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%