SUPPORT COMMUNICATION- SECURITY BULLETIN HPSBHF03657 rev. 3 - NVIDIA GPU Display Driver February 2020 Security Updates

Related Vulnerabilities: CVE-2020-5957   CVE-2020-5958   CVE-2020-5959   CVE-2020-5960   CVE-2020-5961  

NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver and Software which may lead to denial of service, escalation of privileges, code execution, or information disclosure.

Potential Security Impact:
Denial of Service, Escalation of Privileges, Code Execution, Information Disclosure.
Source: HP, HP Product Security Response Team (PSRT)
Reported By: NVIDIA

VULNERABILITY SUMMARY

NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver and Software which may lead to denial of service, escalation of privileges, code execution, or information disclosure.
Reference Number
NVIDIA Security Bulletin 4996 (in English): CVE-2020-5957, CVE-2020-5958, CVE-2020-5959, CVE-2020-5960, CVE-2020-5961, PSR-2020-0042
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
See RESOLUTION section for impacted products.
BACKGROUND
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com
CVSS 3.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2020-5957
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
8.4
CVE-2020-5959
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2020-5958
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
6.7
CVE-2020-5960
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
6.5
CVE-2020-5961
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5
RESOLUTION
NVIDIA has released updates to mitigate the potential vulnerabilities. HP is identifying the affected platforms and the corresponding SoftPaq update versions. See the affected platform tables below.
note:
HP recommends keeping your system up to date with the latest firmware, drivers, and software.
Sign up for HP Subscriptions and get notifications for:
  • Product support eAlerts
  • Driver updates
  • Security bulletin updates

Impacted display adapters

  • NVIDIA GeForce series
    • GT 630, GT 720, GT 730, GT 730A, GT 930MX, GTX 960, GTX 960M, GTX 1050 Max-Q, GTX 1060-B, GTX 1070-B, GTX 1080, MX150, RTX 2060, RTX 2070, RTX 2080
  • NVIDIA Quadro series
    • GP100, GV100, K1100M, K1200, K2000, K2100M, K2200, K2200M, K3100M, K4000, K4100M, K420, K4200, K5000, K5100M, K5200, K600, K6000, K610M, K620, M1000M, M1200, M1200M, M2000, M2000M, M2200, M2200M, M3000M, M4000, M4000M, M5000, M5000M, M6000, M6000 24GB, M600M, M620, P1000, P2000, P2200, P400, P3000, P4000, P5000, P5200, P600, P6000, P620, RTX 4000, RTX 5000, RTX 6000, RTX 8000
  • NVIDIA NVS series
    • NVS 510
    • Desktop Workstations support: NVS 310, NVS 315, and NVS 510

Verify your display adapter and identify the driver version

Use Windows Device Manager to see if you have an impacted display adapter.
  1. Search Windows for Device Manager, and then click Device Manager in the list of results.
  2. Double-click Display Adapters.
    If you see one of the NVIDIA products listed in this document (see list above), continue these steps.
  3. Double-click the NVIDIA product.
  4. Select the Driver tab.
  5. Check the driver version. If you have an earlier driver version than what is listed for your product, update the driver using the link provided in this document.
    The driver version can be identified by the last digits of the version number. For example, 10.18.13.6472 is 364.72.
Not available: Softpaq not available due to technical or logistical constraints.

Home PCs

note:
NVIDIA GPU Display Driver and vGPU Software Updates for Home PCs are available via Windows Update; individual HP driver SoftPaqs will not be provided. To get software and driver updates through Windows Update, go to HP PCs - Updating Drivers and Software with Windows Update (Windows 10, 8, 7).

Business Notebooks

Product Name
Operating System
Updated Version
SoftPaq #
SoftPaq Link
HP 340 G4
Windows 10
26.21.14.4223.S.1
SP101665
HP 348 G4
Windows 10
26.21.14.4223.S.1
SP101665
HP EliteBook 1050 G1
Windows 10
4223.F.10
SP101749
HP ProBook 430 G6
Windows 10
26.21.14.4223.F.5
SP101750
HP ProBook 440 G4
Windows 10
4223.F.10
SP101749
HP ProBook 440 G5
Windows 10
4223.F.10
SP101749
HP ProBook 440 G6
Windows 10
26.21.14.4223.F.5
SP101750
HP ProBook 450 G4
Windows 10
4223.F.10
SP101749
HP ProBook 450 G5
Windows 10
4223.F.10
SP101749
HP ProBook 450 G6
Windows 10
26.21.14.4223.F.5
SP101750
HP ProBook 470 G4
Windows 10
4223.F.10
SP101749
HP ProBook 470 G5
Windows 10
4223.F.10
SP101749
HP ProBook x360 440 G1
Windows 10
4223.F.10
SP101749
HP ZBook 15
Windows 10
442.23.F.15
SP101876
HP ZBook 15 G2
Windows 10
442.23.F.15
SP101876
HP ZBook 15 G3
Windows 10
422.23.F.20
SP101741
HP ZBook 15 G4
Windows 10
422.23.F.20
SP101741
HP ZBook 15 G5
Windows 10
422.23.F.20
SP101741
HP ZBook 15 G6
Windows 10
26.21.14.4223.W.10
SP101740
HP ZBook 17
Windows 10
442.23.F.15
SP101876
HP ZBook 17 G2
Windows 10
442.23.F.15
SP101876
HP ZBook 17 G3
Windows 10
422.23.F.20
SP101741
HP ZBook 17 G4
Windows 10
422.23.F.20
SP101741
HP ZBook 17 G5
Windows 10
422.23.F.20
SP101741
HP ZBook 17 G6
Windows 10
26.21.14.4223.W.10
SP101740
HP ZBook Studio G3
Windows 10
422.23.F.20
SP101741
HP ZBook Studio G4
Windows 10
422.23.F.20
SP101741
HP ZBook Studio G5
Windows 10
422.23.F.20
SP101741
HP ZBook Studio x360 G5
Windows 10
422.23.F.20
SP101741
HP ZBook x2 G4
Windows 10
422.23.F.20
SP101741
HP ZHAN 66 Pro 13 G2
Windows 10
26.21.14.4223.F.5
SP101750
HP ZHAN 66 Pro 14 G2
Windows 10
26.21.14.4223.F.5
SP101750
HP ZHAN 66 Pro 15 G2
Windows 10
26.21.14.4223.F.5
SP101750
HP ZHAN 66 Pro G1
Windows 10
4223.F.10
SP101749

Business Desktops

Product Name
Operating System
Updated Version
SoftPaq #
SoftPaq Link
HP 280 G2 Microtower
Windows 10
442.23
SP101851
HP 280 G2 Microtower
Windows 7
442.23
SP101852
HP 280 G2 Small Form Factor
Windows 10
442.23
SP101851
HP 280 G2 Small Form Factor
Windows 7
442.23
SP101852
HP 280 G3 Microtower
Windows 10
442.23
SP101851
HP 280 G3 Microtower
Windows 7
442.23
SP101852
HP 280 G3 PCI Microtower
Windows 10
442.23
SP101851
HP 280 G3 PCI Microtower
Windows 7
442.23
SP101852
HP 280 Pro G2 Microtower
Windows 10
442.23
SP101851
HP 280 Pro G2 Microtower
Windows 7
442.23
SP101852
HP 280 Pro G3 Microtower
Windows 10
442.23
SP101851
HP 280 Pro G3 Microtower
Windows 7
442.23
SP101852
HP 282 Pro G3 Microtower
Windows 10
442.23
SP101851
HP 282 Pro G3 Microtower
Windows 7
442.23
SP101852
HP 285 Pro G2 Microtower
Windows 10
442.23
SP101851
HP 285 Pro G2 Microtower
Windows 7
442.23
SP101852
HP 286 Pro G2 Microtower
Windows 10
442.23
SP101851
HP 286 Pro G2 Microtower
Windows 7
442.23
SP101852
HP 288 Pro G2 Microtower
Windows 10
442.23
SP101851
HP 288 Pro G2 Microtower
Windows 7
442.23
SP101852
HP 288 Pro G3 Microtower
Windows 10
442.23
SP101851
HP 288 Pro G3 Microtower
Windows 7
442.23
SP101852
HP 290 G1 Microtower
Windows 10
442.23
SP101851
HP 290 G1 Microtower PC
Windows 7
442.23
SP101852
HP 402 G1 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP Desktop Pro Microtower
Windows 10
442.23
SP101851
HP Desktop Pro Microtower PC
Windows 7
442.23
SP101852
HP Desktop Pro PCI Microtower PC
Windows 10
442.23
SP101851
HP Desktop Pro PCI Microtower PC
Windows 7
442.23
SP101852
HP EliteDesk 705 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G2 Microtower
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 705 G2 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G2 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 705 G3 Microtower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G3 Microtower
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 705 G3 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G3 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 705 G4 Microtower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G4 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G4 Workstation Edition
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 705 G5 Small Form Factor
Windows 10
26.21.14.4223
SP101752
HP EliteDesk 800 G1 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G1 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G1 Ultra-slim
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G2 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G2 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 800 G2 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G2 Tower
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 800 G3 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G3 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 800 G3 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G3 Tower
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 800 G4 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G4 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G4 Workstation Edition
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 800 G5 Small Form Factor
Windows 10
26.21.14.4223
SP101752
HP EliteDesk 800 G5 Tower
Windows 10
26.21.14.4223
SP101752
HP EliteDesk 880 G1 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 880 G2 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 880 G2 Tower
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 880 G3 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 880 G3 Tower
Windows 7
26.21.14.4223
SP101754
HP EliteDesk 880 G4 Tower
Windows 10
26.21.14.4223
SP101753
HP EliteDesk 880 G5 Tower
Windows 10
26.21.14.4223
SP101752
HP ProDesk 400 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G1 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G2 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G2.5 Small Form Factor
Windows 10
Not available
Not available
Not available
HP ProDesk 400 G3 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G3 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G4 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G4 Microtower
Windows 7
26.21.14.4223
SP101754
HP ProDesk 400 G4 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G4 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP ProDesk 400 G5 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 400 G6 Microtower
Windows 10
26.21.14.4223
SP101752
HP ProDesk 400 G6 Small Form Factor
Windows 10
26.21.14.4223
SP101752
HP ProDesk 405 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 405 G4 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 480 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 480 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 480 G3 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 480 G4 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 480 G4 Microtower
Windows 7
26.21.14.4223
SP101754
HP ProDesk 480 G6 Microtower
Windows 10
26.21.14.4223
SP101752
HP ProDesk 485 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 490 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 490 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 490 G3 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 498 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 498 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G1 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G1 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G2 Microtower
Windows 7
26.21.14.4223
SP101754
HP ProDesk 600 G2 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G2 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP ProDesk 600 G3 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G3 Microtower
Windows 7
26.21.14.4223
SP101754
HP ProDesk 600 G3 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G3 Small Form Factor
Windows 7
26.21.14.4223
SP101754
HP ProDesk 600 G4 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G4 Microtower (with PCI slot)
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G4 Small Form Factor
Windows 10
26.21.14.4223
SP101753
HP ProDesk 600 G5 Microtower
Windows 10
26.21.14.4223
SP101752
HP ProDesk 600 G5 Microtower (with PCI slot)
Windows 10
26.21.14.4223
SP101752
HP ProDesk 600 G5 Small Form Factor
Windows 10
26.21.14.4223
SP101752
HP ProDesk 680 G1 Tower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 680 G2 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 680 G2 Microtower
Windows 7
26.21.14.4223
SP101754
HP ProDesk 680 G3 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 680 G3 Microtower
Windows 7
26.21.14.4223
SP101754
HP ProDesk 680 G4 Microtower
Windows 10
26.21.14.4223
SP101753
HP ProDesk 680 G4 Microtower (with PCI slot)
Windows 10
26.21.14.4223
SP101752
HP Z1 Entry Tower G5
Windows 10
26.21.14.4223
SP101752
HP Zhan 86 Pro G1 Microtower
Windows 10
442.23
SP101851
HP Zhan 86 Pro G1 Microtower
Windows 7
442.23
SP101852

Desktop Workstations PCs

Product Name
Operating System
Updated Version
SoftPaq #
SoftPaq Link
HP Z240 Small Form Factor Workstation
Windows 10
442.50
SP101774
HP Z240 Small Form Factor Workstation (NVS)
Windows 10
392.59
SP102370
HP Z240 Tower Workstation
Windows 10
442.50
SP101774
HP Z240 Tower Workstation (NVS)
Windows 10
392.59
SP102370
HP Z440 Workstation
Windows 10
442.50
SP101774
HP Z440 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z640 Workstation
Windows 10
442.50
SP101774
HP Z640 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z840 Workstation
Windows 10
442.50
SP101774
HP Z840 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z1 All-in-One G3 Workstation
Windows 10
442.50
SP101774
HP Z1 All-in-One G3 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z2 Mini G3 Workstation
Windows 10
442.50
SP101774
HP Z2 Mini G3 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z2 Mini G4 Workstation
Windows 10
442.50
SP101774
HP Z2 Mini G4 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z2 Small Form Factor G4 Workstation
Windows 10
442.50
SP101774
HP Z2 Small Form Factor G4 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z2 Tower G4 Workstation
Windows 10
442.50
SP101774
HP Z2 Tower G4 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z4 G4 Workstation (Xeon W)
Windows 10
442.50
SP101774
HP Z4 G4 Workstation (Xeon W) (NVS)
Windows 10
392.59
SP102370
HP Z6 G4 Workstation
Windows 10
442.50
SP101774
HP Z6 G4 Workstation (NVS)
Windows 10
392.59
SP102370
HP Z8 G4 Workstation
Windows 10
442.50
SP101774
HP Z8 G4 Workstation (NVS)
Windows 10
392.59
SP102370

Retail Point-of-Sale systems

Product Name
Operating System
Updated Version
SoftPaq #
SoftPaq Link
HP Engage Flex Pro Retail System
Windows 10
26.21.14.4223
SP101760
HP Engage Flex Pro-C Retail System
Windows 10
26.21.14.4223
SP101760
HP RP5 Retail System Model 5810
Windows 10
26.21.14.4223
SP101753
HP RP5 Retail System Model 5810
Windows 7
26.21.14.4223
SP101754

Immersive PCs

HP Product Name (NVIDIA Card)
Operating System
Updated Version
SoftPaq #
SoftPaq Link
Sprout Pro by HP G2 (GeForce GTX960M)
Windows 10
26.21.14.4205
SP101931
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, visit https://www.hp.com/go/contacthp to learn about your HP support options.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp-security-alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via email, visit https://www.hp.com/go/alerts.
Security Bulletin Archive: To view released Security Bulletins, search the HP Support Site for "security bulletin".
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
GN
HP General Software
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin.HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action.HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin.To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version: 1 – 28 February 2020 Initial release. Version: 2 – 28 April 2020 Added direct link to NVIDIA bulletin in References; updated version and SoftPaq information. Version: 3 - 14 May 2020 Updated versions and SoftPaq information for Business Desktops and added Desktop Workstation table entries for NVS devices.