7.2
CVSSv2

CVE-2013-0109

Published: 08/04/2013 Updated: 09/04/2013
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The NVIDIA driver prior to 307.78, and Release 310 prior to 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application.

Vulnerable Product Search on Vulmon Subscribe to Product

nvidia display driver 310.00

nvidia display driver

Exploits

## # This module requires Metasploit: http//metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## require 'msf/core' require 'rex' require 'msf/core/post/common' require 'msf/core/post/windows/priv' require 'msf/core/post/windows/process' require 'msf/core/post/windows/reflective_dll_injection' require 'msf/co ...
The named pipe, \pipe\nsvr, has a NULL DACL allowing any authenticated user to interact with the service It contains a stacked based buffer overflow as a result of a memmove operation Note the slight spelling differences: the executable is 'nvvsvcexe', the service name is 'nvsvc', and the named pipe is 'nsvr' This exploit automatically targets ...