PT-2017-1388 · Nvidia · Nvidia Gpu Driver

Nathan Crandall

·

Published

2017-03-08

·

Updated

2019-10-03

·

CVE-2017-0306

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NVIDIA GPU driver versions prior to the fixed version
Description The issue is related to insufficient access control in the NVIDIA GPU driver for the Android operating system, allowing a remote attacker to launch an application with the privileges of the current user. A local malicious application can execute arbitrary code within the context of the kernel, potentially leading to a local permanent device compromise. This may require reflashing the operating system to repair the device.
Recommendations For versions prior to the fixed version, consider restricting access to the kernel to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00528
CVE-2017-0306

Affected Products

Nvidia Gpu Driver