PT-2020-18867 · Nvidia · Nvidia Geforce Experience+1

Boris Ryutin

+1

·

Published

2020-10-23

·

Updated

2021-07-21

·

CVE-2020-5977

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA GeForce Experience versions prior to 3.20.5.70
Description The issue concerns an uncontrolled search path used to load a node module in the NVIDIA Web Helper NodeJS Web Server, potentially leading to code execution, denial of service, escalation of privileges, and information disclosure.
Recommendations For versions prior to 3.20.5.70, update to version 3.20.5.70 or later to resolve the issue.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5977

Affected Products

Nvidia Geforce Experience
Nvidia Web Helper Nodejs Web Server