PT-2017-1384 · Nvidia · Nvidia Gpu Driver
Billy Lau
·
Published
2017-03-08
·
Updated
2019-10-03
·
CVE-2017-0335
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NVIDIA GPU driver versions prior to the fixed version
Description
The issue is related to insufficient access control in the NVIDIA GPU driver for the Android operating system, allowing a remote attacker to launch an application with the privileges of the current user. A local malicious application can execute arbitrary code within the context of the kernel, potentially leading to a local permanent device compromise. This may require reflashing the operating system to repair the device.
Recommendations
For versions prior to the fixed version, consider restricting access to the kernel to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nvidia Gpu Driver