SUPPORT COMMUNICATION- SECURITY BULLETIN HPSBHF03690 rev. 3 - NVIDIA GPU Display Driver September 2020 Security Updates

Related Vulnerabilities: CVE-2020-5979   CVE-2020-5980   CVE-2020-5981   CVE-2020-5982   CVE-2020-5983   CVE-2020-5984   CVE-2020-5985   CVE-2020-5886   CVE-2020-5887   CVE-2020-5988   CVE-2020-5889  

NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver which might allow escalation of privileges, code execution, denial of service, and/or information disclosure. For detailed information on the vulnerabilities, visit the NVIDIA Product Security (in English) page.

Potential Security Impact:
Escalation of Privilege, Code Execution, Denial of Service, Information Disclosure.
Source: HP, HP Product Security Response Team (PSRT)
Reported By: NVIDIA

VULNERABILITY SUMMARY

NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver which might allow escalation of privileges, code execution, denial of service, and/or information disclosure.
For detailed information on the vulnerabilities, visit the NVIDIA Product Security (in English) page.
Reference Number
NVIDIA Security Bulletin 5075 - GPU Display Driver September 2020: CVE-2020-5979, CVE-2020-5980, CVE-2020-5981, CVE-2020-5982; PSR-2020-0200.
HP does not distribute NVIDIA vGPU Software and is not impacted by CVE-2020-5983, CVE-2020-5984, CVE-2020-5985, CVE-2020-5886, CVE-2020-5887, CVE-2020-5988, and CVE-2020-5889.
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
See RESOLUTION section for impacted products.
BACKGROUND
For a PGP signed version of this security bulletin, please write to: hp-security-alert@hp.com.
CVSS 3.1 Base Metrics
Reference
Base Vector
Base Score
CVE-2020-5979
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5980
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5981
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
7.8
CVE-2020-5982
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
7.4
RESOLUTION
NVIDIA has released updates to mitigate the potential vulnerabilities. HP has identified affected platforms and the corresponding SoftPaqs with minimum versions that mitigate the potential vulnerability. See the affected platforms listed below.
Newer versions might become available and the minimum versions listed below might become obsolete.  If a SoftPaq Link becomes invalid, check the HP Customer Support - Software and Driver Downloads site to obtain the latest update for your product model.
HP recommends keeping your system up to date with the latest firmware and software.
note:
This bulletin might be updated when new information and/or SoftPaqs are available. Sign up for HP Subscriptions to be notified and receive:
  • Product support eAlerts
  • Driver updates
  • Security bulletin updates

Impacted display adapters

  • NVIDIA GeForce series
    • GT 630, GT 720, GT 730, GT 730A, GT 930MX, GTX 960, GTX 960M, GTX 1050 Max-Q, GTX 1060-B, GTX 1070-B, GTX 1080, MX150, RTX 2060, RTX 2070, and RTX 2080
  • NVIDIA Quadro series
    • 410, GP100, GV100, K1100M, K1200, K2000, K2100M, K2200, K2200M, K3100M, K4000, K4100M, K420, K4200, K5000, K5100M, K5200, K600, K6000, K610M, K620, M1000M, M1200, M1200M, M2000, M2000M, M2200, M2200M, M3000M, M4000, M4000M, M5000, M5000M, M6000, M6000 24GB, M600M, M620, P1000, P2000, P2200, P400, P3000, P4000, P5000, P5200, P600, P6000, P620, RTX 4000, RTX 5000, RTX 6000, RTX 8000, T1000, and T2000
  • NVIDIA NVS series
    • NVS 510
    • Desktop Workstations support: NVS 310, NVS 315, and NVS 510
  • NVIDIA Tesla series
    • K20c and K40c

Verify your display adapter and identify the driver version

Use Windows Device Manager to see if you have an impacted display adapter.
  1. Search Windows for Device Manager, and then click Device Manager in the list of results.
  2. Double-click Display Adapters.
    If you see one of the NVIDIA products listed in this document (see list above), continue these steps.
  3. Double-click the NVIDIA product.
  4. Click the Driver tab.
  5. Check the driver version. If you have an earlier driver version than what is listed for your product, update the driver using the link provided in this document.
    The driver version can be identified by the last digits of the version number. For example, 26.21.14.4423 is 444.23.
Pending: SoftPaq is in progress.
Under investigation: System under investigation for impact, or SoftPaq under investigation for feasibility/availability.
Not available: SoftPaq not available due to technical or logistical constraints.
Check support page: The listed SoftPaq has been removed from download site. SoftPaqs with newer versions may be available on the HP Customer Support - Software and Driver Downloads site to obtain the latest update for your product model.

Home Desktops

note:
NVIDIA GPU Display Driver and vGPU Software Updates for Home PCs are available via Windows Update, individual HP driver SoftPaqs will not be provided. To get software and driver updates through Windows update, go to HP PCs - Updating Drivers and Software with Windows Update (Windows 10, 8, 7).

Business Notebooks

Product Name
Minimum Version
SoftPaq #
SoftPaq Link
HP 340 G4
27.21.14.5225
SP110386
HP 348 G4
27.21.14.5225
SP110386
HP EliteBook 1050 G1
27.21.14.5225.F.1
SP110221
HP EliteBook 850 G7
27.21.14.5225.W.3
SP110220
HP ProBook 440 G4
27.21.14.5225.F.1
SP110221
HP ProBook 440 G5
27.21.14.5225.F.1
SP110221
HP ProBook 440 G6
27.21.14.5225.W.2
SP110217
HP ProBook 440 G7
27.21.14.5225.W.2
SP110217
HP ProBook 450 G4
27.21.14.5225.F.1
SP110221
HP ProBook 450 G5
27.21.14.5225.F.1
SP110221
HP ProBook 450 G6
27.21.14.5225.W.2
SP110217
HP ProBook 450 G7
27.21.14.5225.W.2
SP110217
HP ProBook 470 G4
27.21.14.5225.F.1
SP110221
HP ProBook 470 G5
27.21.14.5225.F.1
SP110221
HP ProBook 630 G8
27.21.14.5225.W.3
SP110227
HP ProBook 640 G8
27.21.14.5225.W.3
SP110227
HP ProBook 650 G8
27.21.14.5225.W.3
SP110227
HP ProBook x360 440 G1
27.21.14.5225.F.1
SP110221
HP ZBook 15 G3
27.21.14.5225.F.1
SP110221
HP ZBook 15 G4
27.21.14.5225.F.1
SP110221
HP ZBook 15 G5
27.21.14.5225.F.1
SP110221
HP ZBook 15 G6
27.21.14.5225.W.2
SP110217
HP ZBook 17 G3
27.21.14.5225.F.1
SP110221
HP ZBook 17 G4
27.21.14.5225.F.1
SP110221
HP ZBook 17 G5
27.21.14.5225.F.1
SP110221
HP ZBook 17 G6
27.21.14.5225.W.2
SP110217
HP ZBook Create G7
27.21.14.5225.W.15
SP110227
HP ZBook Firefly 14 G7
27.21.14.5225.W.3
SP110220
HP ZBook Firefly 15 G7
27.21.14.5225.W.3
SP110220
HP ZBook Fury 15 G7
27.21.14.5225.W.15
SP110227
HP ZBook Fury 17 G7
27.21.14.5225.W.15
SP110227
HP ZBook Power G7
27.21.14.5225.W.3
SP110264
HP ZBook Studio G3
27.21.14.5225.F.1
SP110221
HP ZBook Studio G4
27.21.14.5225.F.1
SP110221
HP ZBook Studio G5
27.21.14.5225.F.1
SP110221
HP ZBook Studio G7
27.21.14.5225.W.15
SP110227
HP ZBook Studio x360 G5
27.21.14.5225.F.1
SP110221
HP ZBook x2 G4
27.21.14.5225.F.1
SP110221
HP ZHAN 66 Pro 14 G2
27.21.14.5225.W.2
SP110217
HP ZHAN 66 Pro 14 G3
27.21.14.5225.W.2
SP110217
HP ZHAN 66 Pro 14 G4
27.21.14.5225.W.3
SP110227
HP ZHAN 66 Pro 15 G2
27.21.14.5225.W.2
SP110217
HP ZHAN 66 Pro 15 G3
27.21.14.5225.W.2
SP110217
HP ZHAN 66 Pro G1
27.21.14.5225.F.1
SP110221

Business Desktops

Product Name
Component Type
Minimum Version
SoftPaq #
SoftPaq Link
HP 280 G2 Small Form Factor
Windows 10
27.21.14.5211
SP110365
HP 280 G2 Small Form Factor
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP 280 G3 Microtower
Windows 10
27.21.14.5211
SP110365
HP 280 G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP 280 G3 PCI Microtower
Windows 10
27.21.14.5211
SP110365
HP 280 G3 PCI Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP 280 Pro G3 Microtower
Windows 10
27.21.14.5211
SP110365
HP 280 Pro G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP 282 Pro G3 Microtower
Windows 10
27.21.14.5211
SP110365
HP 282 Pro G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP 288 Pro G3 Microtower
Windows 10
27.21.14.5211
SP110365
HP 288 Pro G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP 290 G1 Microtower
Windows 10
27.21.14.5211
SP110365
HP 290 G1 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP Desktop Pro Microtower
Windows 10
27.21.14.5211
SP110365
HP Desktop Pro Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366
HP EliteDesk 705 G2 Microtower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G2 Microtower
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP EliteDesk 705 G2 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G2 Small Form Factor
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP EliteDesk 705 G3 Microtower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP EliteDesk 705 G3 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G3 Small Form Factor
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP EliteDesk 705 G4 Microtower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G4 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G4 Workstation Edition
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 705 G5 Small Form Factor
Windows 10
27.21.14.5211
SP110203
HP EliteDesk 800 G2 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G2 Small Form Factor
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP EliteDesk 800 G2 Tower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G2 Tower
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP EliteDesk 800 G3 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G3 Small Form Factor
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP EliteDesk 800 G3 Tower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G3 Tower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP EliteDesk 800 G4 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G4 Tower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G4 Workstation Edition
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 800 G5 Small Form Factor
Windows 10
27.21.14.5211
SP110203
HP EliteDesk 800 G5 Tower
Windows 10
27.21.14.5211
SP110203
HP EliteDesk 800 G6 Desktop Mini
Windows 10/Windows 10 IOT 19H2 CBB
27.21.14.5211
SP110187
HP EliteDesk 800 G6 Small Form Factor
Windows 10
452.39
SP110420
HP EliteDesk 800 G6 Tower
Windows 10
27.21.14.5211
SP110187
HP EliteDesk 800 G6 Tower
Windows 10 (Quadro)
452.39
SP110420
HP EliteDesk 805 G6 Desktop Mini
Windows 10
27.21.14.5211
SP110187
HP EliteDesk 805 G6 Small Form Factor
Windows 10
452.39
SP110420
HP EliteDesk 880 G2 Tower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 880 G2 Tower
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP EliteDesk 880 G3 Tower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 880 G3 Tower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP EliteDesk 880 G4 Tower
Windows 10
27.21.14.5211
SP110204
HP EliteDesk 880 G5 Tower
Windows 10
27.21.14.5211
SP110203
HP EliteDesk 880 G6 Tower
Windows 10
27.21.14.5211
SP110187
HP EliteDesk 880 G6 Tower
Windows 10 (Quadro)
452.39
SP110420
HP EliteOne 800 G6 24 All-in-One
Windows 10/Windows 10 IOT 19H2 CBB
27.21.14.5211
SP110187
HP EliteOne 800 G6 27 All-in-One
Windows 10/Windows 10 IOT 19H2 CBB
27.21.14.5211
SP110187
HP ProDesk 400 G4 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 400 G4 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP ProDesk 400 G4 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP ProDesk 400 G4 Small Form Factor
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP ProDesk 400 G5 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 400 G5 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP ProDesk 400 G6 Microtower
Windows 10
27.21.14.5211
SP110203
HP ProDesk 400 G6 Small Form Factor
Windows 10
27.21.14.5211
SP110203
HP ProDesk 405 G4 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP ProDesk 480 G4 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 480 G4 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP ProDesk 480 G5 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 480 G6 Microtower
Windows 10
27.21.14.5211
SP110203
HP ProDesk 600 G2 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 600 G2 Microtower
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP ProDesk 600 G2 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP ProDesk 600 G2 Small Form Factor
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP ProDesk 600 G3 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 600 G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP ProDesk 600 G3 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP ProDesk 600 G3 Small Form Factor
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP ProDesk 600 G4 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 600 G4 Small Form Factor
Windows 10
27.21.14.5211
SP110204
HP ProDesk 600 G5 Microtower
Windows 10
27.21.14.5211
SP110203
HP ProDesk 600 G5 Microtower (with PCI slot)
Windows 10
27.21.14.5211
SP110203
HP ProDesk 600 G5 Small Form Factor
Windows 10
27.21.14.5211
SP110203
HP ProDesk 600 G6 Microtower
Windows 10
27.21.14.5211
SP110187
HP ProDesk 600 G6 PCI Microtower
Windows 10
27.21.14.5211
SP110187
HP ProDesk 680 G2 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 680 G2 Microtower
Windows 7 (64 bit)/Windows 8.1
27.21.14.5211
SP110205
HP ProDesk 680 G3 Microtower
Windows 10
27.21.14.5211
SP110204
HP ProDesk 680 G3 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110205
HP ProDesk 680 G4 Microtower
Windows 10
27.21.14.5211
SP110203
HP ProDesk 680 G4 Microtower (With PCI slot)
Windows 10
27.21.14.5211
SP110204
HP ProDesk 680 G6 PCI Microtower
Windows 10
27.21.14.5211
SP110187
HP Zhan 86 Pro G1 Microtower
Windows 10
27.21.14.5211
SP110365
HP Zhan 86 Pro G1 Microtower
Windows 7 (64 bit)
27.21.14.5211
SP110366

Workstations

Product Name
Component Type
Minimum Version
SoftPaq #
SoftPaq Link
HP Z1 All-in-One G3 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z1 Entry Tower G5 Workstation
Windows 10 - Quadro series
452.39
SP110420
HP Z1 Entry Tower G6 Workstation
Windows 10 - Quadro series
452.39
SP110420
HP Z2 Mini G3 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z2 Mini G4 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z2 Mini G5 Workstation
Windows 10 - Quadro series
452.39
SP110420
HP Z2 Small Form Factor G4 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z2 Small Form Factor G5 Workstation
Windows 10 - Quadro series
452.39
SP110420
HP Z2 Tower G4 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z2 Tower G5 Workstation
Windows 10 - Quadro series
452.39
SP110420
HP Z238 Microtower Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z240 Small Form Factor Workstation
Windows 10 - NVS series
392.62
SP110849
HP Z240 Small Form Factor Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z240 Tower Workstation
Windows 10 - NVS series
392.62
SP110849
HP Z240 Tower Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z4 G4 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z440 Workstation
Windows 10 - NVS series
392.62
SP110849
HP Z440 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z6 G4 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z640 Workstation
Windows 10 - NVS series
392.62
SP110849
HP Z640 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z8 G4 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z840 Workstation
Windows 10 - NVS series
392.62
SP110849
HP Z840 Workstation
Windows 10 - Quadro series
452.39
SP110419
HP Z VR Backpack G1 Workstation
Windows 10
27.21.14.5671
SP110873

Retail Point-of-Sale

Product Name
Component Type
Minimum Version
SoftPaq #
SoftPaq Link
HP Engage Flex Pro Retail System
Windows 10
452.39
SP110420
HP Engage Flex Pro Retail System
Windows 10 IoT RS5/Windows 10 IoT RS1
452.39
SP110419
HP Engage Flex Pro-C Retail System
Windows 10
452.39
SP110420
HP Engage Flex Pro-C Retail System
Windows 10 IoT RS5/Windows 10 IoT RS1
452.39
SP110419

Immersive PCs

Product Name
Minimum Version
SoftPaq #
SoftPaq Link
Sprout Pro by HP G2 (GeForce GTX960M)
26.21.14.4629 rev. Y
SP110285
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, visit https://www.hp.com/go/contacthp to learn about your HP support options.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp-security-alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via email, visit https://www.hp.com/go/alerts.
Security Bulletin Archive: To view released Security Bulletins, search the HP Support Site for "security bulletin".
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
GN
HP General Software
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin.HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action.HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin.To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version: 1 – 30 September 2020 Initial release. Version: 2 – 16 November 2020 Updated version and SoftPaq information for product tables. Version: 3 – 05 December 2020 Updated version and SoftPaq information for Business Desktop, Workstations, and Retail Point-of-Sale product tables.