PT-2021-13470 · Nvidia · Nvidia Windows Gpu Display Driver
Published
2021-04-21
·
Updated
2022-07-21
·
CVE-2021-1074
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NVIDIA GPU Display Driver for Windows versions R390 driver branch
Description
The issue allows an attacker with local unprivileged system access to potentially replace an application resource with malicious files during the installation process. This requires a user with system administration rights to execute the installer and for the attacker to replace the files within a short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.
Recommendations
For NVIDIA GPU Display Driver for Windows versions R390 driver branch, consider restricting access to the installer to prevent unauthorized execution, and ensure that the installation process is closely monitored to minimize the risk of file replacement. As a temporary workaround, consider implementing additional validation checks on installed files to detect potential tampering.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nvidia Windows Gpu Display Driver