PT-2015-2748 · Nvidia · Nvidia Gpu Graphics Driver

Wesley Daniels

·

Published

2015-11-24

·

Updated

2019-02-13

·

CVE-2015-7866

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NVIDIA GPU graphics driver versions prior to 341.92 NVIDIA GPU graphics driver versions prior to 354.35 NVIDIA GPU graphics driver versions prior to 358.87
Description The issue is related to an unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) within the Control Panel of the NVIDIA GPU graphics driver. This vulnerability can be exploited by a local user to gain privileges via a Trojan horse application. The exploitation can occur when a specially crafted application is executed, potentially allowing an attacker to elevate their privileges.
Recommendations For versions prior to 341.92, update to version 341.92 or later. For versions prior to 354.35, update to version 354.35 or later. For versions prior to 358.87, update to version 358.87 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12113
CVE-2015-7866

Affected Products

Nvidia Gpu Graphics Driver