SUPPORT COMMUNICATION- SECURITY BULLETIN HPSBHF03672 rev. 2 - NVIDIA GPU Display Driver June 2020 Security Updates

Related Vulnerabilities: CVE-2020-5962   CVE-2020-5963   CVE-2020-5964   CVE-2020-5965   CVE-2020-5966   CVE-2020-5967   CVE-2020-5968   CVE-2020-5969   CVE-2020-5970   CVE-2020-5971   CVE-2020-5972   CVE-2020-5973  

NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver and Software which may lead to escalation of privileges, code execution, denial of service, or information disclosure. For detailed information on the vulnerabilities visit the NVIDIA Product Security page at https://www.nvidia.com/security (in English).

Potential Security Impact:
Escalation of Privilege, Code Execution, Denial of Service, Information Disclosure.
Source: HP, HP Product Security Response Team (PSRT)
Reported By: NVIDIA

VULNERABILITY SUMMARY

NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver and Software which may lead to escalation of privileges, code execution, denial of service, or information disclosure.
For detailed information on the vulnerabilities visit the NVIDIA Product Security page at https://www.nvidia.com/security (in English).
Reference Number
NVIDIA Security Bulletin 5031 – NVIDIA GPU Display Driver - June 2020 (in English): CVE-2020-5962, CVE-2020-5963, CVE-2020-5964, CVE-2020-5965, CVE-2020-5966, CVE-2020-5967, CVE-2020-5968, CVE-2020-5969, CVE-2020-5970, CVE-2020-5971, CVE-2020-5972, CVE-2020-5973; PSR-2020-0115
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
See RESOLUTION section for impacted products.
BACKGROUND
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com
CVSS 3.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2020-5962
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5963
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5968
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5969
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5970
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5971
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5964
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
6.5
CVE-2020-5965
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5
CVE-2020-5966
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5
CVE-2020-5967
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5
CVE-2020-5972
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5
CVE-2020-5973
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
4.4
RESOLUTION
NVIDIA has released updates to mitigate the potential vulnerabilities. HP is identifying the affected platforms and the corresponding SoftPaq update versions. See the affected platforms listed below.
note:
This bulletin might be updated when new information and/or SoftPaqs are available. Sign up for HP Subscriptions to be notified and receive:
  • Product support eAlerts
  • Driver updates
  • Security bulletin updates
HP recommends keeping your system up to date with the latest firmware and software.

Impacted display adapters

  • NVIDIA GeForce series
    • GT 630, GT 720, GT 730, GT 730A, GT 930MX, GTX 960, GTX 960M, GTX 1050 Max-Q, GTX 1060-B, GTX 1070-B, GTX 1080, MX150, RTX 2060, RTX 2070, RTX 2080
  • NVIDIA Quadro series
    • 410, GP100, GV100, K1100M, K1200, K2000, K2100M, K2200, K2200M, K3100M, K4000, K4100M, K420, K4200, K5000, K5100M, K5200, K600, K6000, K610M, K620, M1000M, M1200, M1200M, M2000, M2000M, M2200, M2200M, M3000M, M4000, M4000M, M5000, M5000M, M6000, M6000 24GB, M600M, M620, P1000, P2000, P2200, P400, P3000, P4000, P5000, P5200, P600, P6000, P620, RTX 4000, RTX 5000, RTX 6000, RTX 8000, T1000, T2000
  • NVIDIA NVS series
    • NVS 510
    • Desktop Workstations support: NVS 310, NVS 315, and NVS 510
  • NVIDIA Tesla series
    • K20c, K40c

Verify your display adapter and identify the driver version

Use Windows Device Manager to see if you have an impacted display adapter.
  1. Search Windows for Device Manager. Click Device manager in the list of results.
  2. Double-click Display Adapters.
    If one of the NVIDIA products listed in this document (see list above), continue these steps.
  3. Double-click the NVIDIA product.
  4. Select the Driver tab.
  5. Confirm the driver version. The driver version can be identified by the last digits of the version number. For example, 26.21.14.4223 is 442.23. If an earlier driver version is listed for your product, use the link provided in this document to update the driver.
Pending: Softpaq is in progress.
Under investigation: System under investigation for impact, or Softpaq under investigation for feasibility/availability.
Not available: Softpaq not available due to technical or logistical constraints.

Home PCs

note:
NVIDIA GPU Display Driver and vGPU software updates for HP home notebook and desktop PCs are available via Windows Update. Individual HP driver SoftPaqs will not be provided. For information about downloading software and driver updates through Windows update, go to HP PCs - Updating Drivers and Software with Windows Update (Windows 10, 8, 7).

Business Notebook PCs

Product Name
Component Type
Updated Version
SoftPaq #
SoftPaq Link
HP 340 G4
Win10
27.21.14.5167
SP107482
HP 346 G4
Win10
27.21.14.5167
SP107482
HP 348 G4
Win10
27.21.14.5167
SP107482
HP EliteBook 1050 G1
Win10
26.21.14.4318.F.12
SP105857
HP EliteBook 850 G7
Win10
26.21.14.4318.W.2
SP105810
HP ProBook 430 G7
Win10
26.21.14.4318.F.7
SP105833
HP ProBook 440 G4
Win10
26.21.14.4318.F.12
SP105857
HP ProBook 440 G5
Win10
26.21.14.4318.F.12
SP105857
HP ProBook 440 G6
Win10
26.21.14.4318.F.7
SP105833
HP ProBook 440 G7
Win10
26.21.14.4318.F.7
SP105833
HP ProBook 450 G4
Win10
26.21.14.4318.F.12
SP105857
HP ProBook 450 G5
Win10
26.21.14.4318.F.12
SP105857
HP ProBook 450 G6
Win10
26.21.14.4318.F.7
SP105833
HP ProBook 450 G7
Win10
26.21.14.4318.F.7
SP105833
HP ProBook 470 G4
Win10
26.21.14.4318.F.12
SP105857
HP ProBook 470 G5
Win10
26.21.14.4318.F.12
SP105857
HP ProBook x360 440 G1
Win10
26.21.14.4318.F.12
SP105857
HP ZBook 15 G3
Win10
26.21.14.4318.F.24
SP105809
HP ZBook 15 G4
Win10
26.21.14.4318.F.24
SP105809
HP ZBook 15 G5
Win10
26.21.14.4318.F.24
SP105809
HP ZBook 15 G6
Win10
26.21.14.4318.C18
SP105953
HP ZBook 17 G3
Win10
26.21.14.4318.F.24
SP105809
HP ZBook 17 G4
Win10
26.21.14.4318.F.24
SP105809
HP ZBook 17 G5
Win10
26.21.14.4318.F.24
SP105809
HP ZBook 17 G6
Win10
26.21.14.4318.C18
SP105953
HP ZBook Firefly 14 G7
Win10
26.21.14.4318.W.2
SP105810
HP ZBook Firefly 15 G7
Win10
26.21.14.4318.W.2
SP105810
HP ZBook Studio G3
Win10
26.21.14.4318.F.24
SP105809
HP ZBook Studio G4
Win10
26.21.14.4318.F.24
SP105809
HP ZBook Studio G5
Win10
26.21.14.4318.F.24
SP105809
HP ZBook Studio x360 G5
Win10
26.21.14.4318.F.24
SP105809
HP ZBook x2 G4
Win10
26.21.14.4318.F.24
SP105809
HP ZHAN 66 Pro 14 G2
Win10
26.21.14.4318.F.7
SP105833
HP ZHAN 66 Pro 14 G3
Win10
26.21.14.4318.F.7
SP105833
HP ZHAN 66 Pro 15 G2
Win10
26.21.14.4318.F.7
SP105833
HP ZHAN 66 Pro 15 G3
Win10
26.21.14.4318.F.7
SP105833
HP ZHAN 66 Pro G1
Win10
26.21.14.4318.F.12
SP105857

Business Desktop PCs

Product Name
Component Version
Updated Version
SoftPaq#
SoftPaq Link
HP 280 G3 Microtower
Win10
26.21.14.4336
SP107313
HP 280 G3 Microtower
Win7 64
26.21.14.4336
SP107317
HP 280 G3 PCI Microtower
Win10
26.21.14.4336
SP107313
HP 280 G3 PCI Microtower
Win7 64
26.21.14.4336
SP107317
HP 280 Pro G3 Microtower
Win10
26.21.14.4336
SP107313
HP 280 Pro G3 Microtower
Win7 64
26.21.14.4336
SP107317
HP 282 Pro G3 Microtower
Win10
26.21.14.4336
SP107313
HP 282 Pro G3 Microtower
Win7 64
26.21.14.4336
SP107317
HP 288 ProG3 Microtower
Win10
26.21.14.4336
SP107313
HP 288 ProG3 Microtower
Win7 64
26.21.14.4336
SP107317
HP 290 G1 Microtower
Win10
26.21.14.4336
SP107313
HP 290 G1 Microtower
Win7 64
26.21.14.4336
SP107317
HP Desktop Pro Microtower
Win10
26.21.14.4336
SP107313
HP Desktop Pro Microtower
Win7 64
26.21.14.4336
SP107317
HP EliteDesk 705 G2 Microtower
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G2 Microtower
Win7 64,Win8.1
26.21.14.4336
SP105883
HP EliteDesk 705 G2 Small Form Factor
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G2 Small Form Factor
Win7 64,Win8.1
26.21.14.4336
SP105883
HP EliteDesk 705 G3 Microtower PC
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G3 Microtower PC
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 705 G3 Small Form Factor PC
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G3 Small Form Factor PC
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 705 G4 Microtower
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G4 Small Form Factor
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G4 Workstation Edition
Win10
26.21.14.4336
SP105882
HP EliteDesk 705 G5 Small Form Factor
Win10
26.21.14.4336
SP105861
HP EliteDesk 800 G2 Small Form Factor
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G2 Small Form Factor
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 800 G2 Tower
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G2 Tower
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 800 G3 Small Form Factor
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G3 Small Form Factor
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 800 G3 Tower
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G3 Tower
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 800 G4 Small Form Factor
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G4 Tower
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G4 Workstation Edition
Win10
26.21.14.4336
SP105882
HP EliteDesk 800 G5 Small Form Factor
Win10
26.21.14.4336
SP105861
HP EliteDesk 800 G5 Tower
Win10
26.21.14.4336
SP105861
HP EliteDesk 800 G6 Desktop Mini
Win10
26.21.14.4336
SP105954
HP EliteDesk 880 G2 Tower
Win10
26.21.14.4336
SP105882
HP EliteDesk 880 G2 Tower
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 880 G3 Tower
Win10
26.21.14.4336
SP105882
HP EliteDesk 880 G3 Tower
Win7 64
26.21.14.4336
SP105883
HP EliteDesk 880 G4 Tower
Win10
26.21.14.4336
SP105882
HP EliteDesk 880 G5 Tower
Win10
26.21.14.4336
SP105861
HP ProDesk 400 G3 Microtower
Not available
Not available
Not available
Not available
HP ProDesk 400 G3 Small Form Factor
Not available
Not available
Not available
Not available
HP ProDesk 400 G4 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 400 G4 Microtower
Win7 64
26.21.14.4336
SP105883
HP ProDesk 400 G4 Small Form Factor
Win10
26.21.14.4336
SP105882
HP ProDesk 400 G4 Small Form Factor
Win7 64,Win8.1
26.21.14.4336
SP105883
HP ProDesk 400 G5 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 400 G5 Small Form Factor
Win10
26.21.14.4336
SP105882
HP ProDesk 400 G6 Microtower
Win10
26.21.14.4336
SP105861
HP ProDesk 400 G6 Small Form Factor
Win10
26.21.14.4336
SP105861
HP ProDesk 405 G4 Small Form Factor
Win10
26.21.14.4336
SP105882
HP ProDesk 480 G3 Microtower
Not available
Not available
Not available
Not available
HP ProDesk 480 G4 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 480 G4 Microtower
Win7 64
26.21.14.4336
SP105883
HP ProDesk 480 G5 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 480 G6 Microtower
Win10
26.21.14.4336
SP105861
HP ProDesk 490 G3 Microtower
Not available
Not available
Not available
Not available
HP ProDesk 600 G2 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G2 Microtower
Win7 64
26.21.14.4336
SP105883
HP ProDesk 600 G2 Small Form Factor
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G2 Small Form Factor
Win7 64
26.21.14.4336
SP105883
HP ProDesk 600 G3 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G3 Microtower
Win7 64
26.21.14.4336
SP105883
HP ProDesk 600 G3 Small Form Factor
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G3 Small Form Factor
Win7 64,Win8.1
26.21.14.4336
SP105883
HP ProDesk 600 G4 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G4 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G4 Microtower (with PCI slot)
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G4 Small Form Factor
Win10
26.21.14.4336
SP105882
HP ProDesk 600 G5 Microtower
Win10
26.21.14.4336
SP105861
HP ProDesk 600 G5 Microtower (with PCI slot)
Win10
26.21.14.4336
SP105861
HP ProDesk 600 G5 Small Form Factor
Win10
26.21.14.4336
SP105861
HP ProDesk 680 G2 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 680 G2 Microtower
Win7 64
26.21.14.4336
SP105883
HP ProDesk 680 G3 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 680 G3 Microtower
Win7 64
26.21.14.4336
SP105883
HP ProDesk 680 G4 Microtower
Win10
26.21.14.4336
SP105882
HP ProDesk 680 G4 Microtower (With PCI slot)
Win10
26.21.14.4336
SP105861
HP Z1 Entry Tower G5
Win10
26.21.14.4336
SP105861
HP Zhan 86 Pro G1 Microtower
Win10
26.21.14.4336
SP107313
HP Zhan 86 Pro G1 Microtower
Win7 64
26.21.14.4336
SP107317

Desktop Workstations PCs

Product Name
Updated Version
SoftPaq#
SoftPaq Link
HP Z1 G3 Workstation (NVS)
392.61
SP106133
HP Z1 G3 Workstation (Quadro)
451.48
SP102149
HP Z2 Mini G3 Workstation (NVS)
392.61
SP106133
HP Z2 Mini G3 Workstation (Quadro)
451.48
SP102149
HP Z2 Mini G4 Workstation (NVS)
392.61
SP106133
HP Z2 Mini G4 Workstation (Quadro)
451.48
SP102149
HP Z2 SFF G4 Workstation (NVS)
392.61
SP106133
HP Z2 SFF G4 Workstation (Quadro)
451.48
SP102149
HP Z2 TWR G4 Workstation (NVS)
392.61
SP106133
HP Z2 TWR G4 Workstation (Quadro)
451.48
SP102149
HP Z238 Microtower Workstation (NVS)
392.61
SP106133
HP Z238 Microtower Workstation (Quadro)
451.48
SP102149
HP Z240 SFF Workstation (NVS)
392.61
SP106133
HP Z240 SFF Workstation (Quadro)
451.48
SP102149
HP Z240 Tower Workstation (NVS)
392.61
SP106133
HP Z240 Tower Workstation (Quadro)
451.48
SP102149
HP Z4 G4 Workstation (NVS)
392.61
SP106133
HP Z4 G4 Workstation (Quadro)
451.48
SP102149
HP Z440 Workstation (NVS)
392.61
SP106133
HP Z440 Workstation (Quadro)
451.48
SP102149
HP Z6 G4 Workstation (NVS)
392.61
SP106133
HP Z6 G4 Workstation (Quadro)
451.48
SP102149
HP Z640 Workstation (NVS)
392.61
SP106133
HP Z640 Workstation (Quadro)
451.48
SP102149
HP Z8 G4 Workstation (NVS)
392.61
SP106133
HP Z8 G4 Workstation (Quadro)
451.48
SP102149
HP Z840 Workstation (NVS)
392.61
SP106133
HP Z840 Workstation (Quadro)
451.48
SP102149
HP Z VR Backpack Workstation G1
451.48
SP107632

Retail Point-of-Sale systems

Product Name
Component Type
Updated Version
SoftPaq#
SoftPaq Link
HP Engage Flex Pro Retail System
Win10
451.48
SP103737
HP Engage Flex Pro Retail System
Win10 IoT RS5/ Win10 IoT RS5
451.48
SP102149
HP Engage Flex Pro-C Retail System
Win10
451.48
SP103737
HP Engage Flex Pro-C Retail System
Win10 IoT RS5/ Win10 IoT RS5
451.48
SP102149

Immersive PCs

Product Name
Updated Version
SoftPaq #
SoftPaq Link
Sprout Pro by HP G2
26.21.14.4318
SP105593
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, visit https://www.hp.com/go/contacthp to learn about your HP support options.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp-security-alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via email, visit https://www.hp.com/go/alerts.
Security Bulletin Archive: To view released Security Bulletins, search the HP Support Site for "security bulletin".
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
GN
HP General Software
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin.HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action.HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin.To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version: 1 – 24 June 2020 Initial release. Version: 2 – 15 September 2020 Added NVIDIA bulletin ID and link; clarified the CVSS version in the Base Metrics table; updated SoftPaq information for the product tables.