PT-2019-4370 · Nvidia · Nvidia Windows Gpu Display Driver

Publicado

2019-08-06

·

Atualizado

2020-08-24

·

CVE-2019-5687

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions NVIDIA Windows GPU Display Driver (all versions)
Description The issue is related to an incorrect use of default permissions for an object in the kernel mode layer handler for DxgkDdiEscape, exposing it to an unintended actor. This vulnerability in the NVIDIA Windows GPU Display Driver is associated with errors in permission handling, which can be exploited to disclose protected information or cause a denial of service.
Recommendations For all versions, consider restricting access to the nvlddmkm.sys handler for DxgkDdiEscape until a patch is available. As a temporary workaround, avoid using the DxgkDdiEscape function in the NVIDIA Windows GPU Display Driver to minimize the risk of exploitation.

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00091
CVE-2019-5687

Produtos afetados

Nvidia Windows Gpu Display Driver