PT-2020-5801 · Nvidia+2 · Nvidia Windows Gpu Display Driver+2

Thomas E. Carroll

·

Published

2020-06-24

·

Updated

2021-07-21

·

CVE-2020-5963

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NVIDIA Windows GPU Display Driver, all versions
Description: The issue is related to improper access control in the Inter Process Communication APIs of the NVIDIA Windows GPU Display Driver. This may lead to code execution, denial of service, or information disclosure. The vulnerability is also associated with insecure privilege management, which could allow an attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations: For all versions, consider restricting access to the Inter Process Communication APIs as a temporary workaround until a patch is available. Additionally, review and adjust privilege management settings to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01764
CVE-2020-5963
USN-4404-1
USN-4404-2

Affected Products

Linuxmint
Nvidia Windows Gpu Display Driver
Ubuntu