PT-2020-5801 · Nvidia+2 · Nvidia Windows Gpu Display Driver+2
Thomas E. Carroll
·
Published
2020-06-24
·
Updated
2021-07-21
·
CVE-2020-5963
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
NVIDIA Windows GPU Display Driver, all versions
Description:
The issue is related to improper access control in the Inter Process Communication APIs of the NVIDIA Windows GPU Display Driver. This may lead to code execution, denial of service, or information disclosure. The vulnerability is also associated with insecure privilege management, which could allow an attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations:
For all versions, consider restricting access to the Inter Process Communication APIs as a temporary workaround until a patch is available. Additionally, review and adjust privilege management settings to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Nvidia Windows Gpu Display Driver
Ubuntu