PT-2023-1554 · Nvidia · Nvidia Geforce Experience

Minse Kim

·

Published

2023-01-30

·

Updated

2023-02-14

·

CVE-2022-42291

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions NVIDIA GeForce Experience (affected versions not specified)
Description The issue is related to the installer of the NVIDIA GeForce Experience software, where a user may inadvertently delete data from a linked location, potentially leading to data tampering. This occurs due to incorrect link resolution before file access. An attacker does not have explicit control over the exploitation, which requires the user to launch the installer from a compromised directory. The exploitation may allow a remote attacker to delete arbitrary data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insecure Operation on Windows Junction

Link Following

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-01010
CVE-2022-42291

Affected Products

Nvidia Geforce Experience