PT-2015-5142 · Nvidia · Nvidia Gpu Display Driver
James Forshaw
·
Published
2015-03-06
·
Updated
2016-12-08
·
CVE-2015-1170
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NVIDIA Display Driver R304 versions prior to 309.08
NVIDIA Display Driver R340 versions prior to 341.44
NVIDIA Display Driver R343 versions prior to 345.20
NVIDIA Display Driver R346 versions prior to 347.52
Description
The issue allows local users to gain administrator privileges due to improper validation of local client impersonation levels during a "kernel administrator check". This can be achieved via unspecified API calls.
Recommendations
For NVIDIA Display Driver R304 versions prior to 309.08, update to version 309.08 or later.
For NVIDIA Display Driver R340 versions prior to 341.44, update to version 341.44 or later.
For NVIDIA Display Driver R343 versions prior to 345.20, update to version 345.20 or later.
For NVIDIA Display Driver R346 versions prior to 347.52, update to version 347.52 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nvidia Gpu Display Driver