PT-2021-13475 · Nvidia · Nvidia Geforce Experience

Matt Batten

+1

·

Published

2021-04-20

·

Updated

2021-05-18

·

CVE-2021-1079

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA GeForce Experience versions prior to 3.22
Description The issue concerns a vulnerability in GameStream plugins where log files are created using NT/System level permissions. This may lead to code execution, denial of service, or local privilege escalation. However, the attacker does not have control over the consequence of a modification, nor would they be able to leak information as a direct result of the overwrite.
Recommendations For versions prior to 3.22, update to version 3.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the GameStream plugins until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-1079

Affected Products

Nvidia Geforce Experience