PT-2021-13470 · Nvidia · Nvidia Windows Gpu Display Driver

Published

2021-04-21

·

Updated

2022-07-21

·

CVE-2021-1074

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA GPU Display Driver for Windows versions R390 driver branch
Description The issue allows an attacker with local unprivileged system access to potentially replace an application resource with malicious files during the installation process. This requires a user with system administration rights to execute the installer and for the attacker to replace the files within a short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.
Recommendations For NVIDIA GPU Display Driver for Windows versions R390 driver branch, consider restricting access to the installer to prevent unauthorized execution, and ensure that the installation process is closely monitored to minimize the risk of file replacement. As a temporary workaround, consider implementing additional validation checks on installed files to detect potential tampering.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-1074

Affected Products

Nvidia Windows Gpu Display Driver