Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1074

Опубликовано: 21 апр. 2021
Источник: nvd
CVSS3: 7.3
CVSS2: 6.9
EPSS Низкий

Описание

NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
Версия от 390 (включая) до 392.65 (исключая)

EPSS

Процентиль: 29%
0.00107
Низкий

7.3 High

CVSS3

6.9 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.3
github
больше 3 лет назад

NVIDIA Windows GPU Display Driver for Windows, R390 driver branch, contains a vulnerability in its installer where an attacker with local system access may replace an application resource with malicious files. Such an attack may lead to code execution, escalation of privileges, denial of service, or information disclosure.

EPSS

Процентиль: 29%
0.00107
Низкий

7.3 High

CVSS3

6.9 Medium

CVSS2

Дефекты

NVD-CWE-noinfo