PT-2019-17820 · Nvidia · Nvidia Windows Gpu Display Driver
Published
2019-11-09
·
Updated
2022-01-01
·
CVE-2019-5694
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NVIDIA Windows GPU Display Driver, R390 driver version
Description
The issue arises from the incorrect loading of Windows system DLLs by the NVIDIA Control Panel without proper validation of the path or signature, making it susceptible to a binary planting or DLL preloading attack. This could potentially lead to denial of service or information disclosure through code execution, provided the attacker has local system access.
Recommendations
For R390 driver version, update to a version that addresses the DLL loading issue to prevent potential code execution and information disclosure.
As a temporary workaround, consider restricting local system access to minimize the risk of exploitation.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nvidia Windows Gpu Display Driver