PT-2021-13475 · Nvidia · Nvidia Geforce Experience
Matt Batten
+1
·
Published
2021-04-20
·
Updated
2021-05-18
·
CVE-2021-1079
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
NVIDIA GeForce Experience versions prior to 3.22
Description
The issue concerns a vulnerability in GameStream plugins where log files are created using NT/System level permissions. This may lead to code execution, denial of service, or local privilege escalation. However, the attacker does not have control over the consequence of a modification, nor would they be able to leak information as a direct result of the overwrite.
Recommendations
For versions prior to 3.22, update to version 3.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the GameStream plugins until a patch is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nvidia Geforce Experience