7.7
CVSSv2

CVE-2015-7865

Published: 24/11/2015 Updated: 13/02/2019
CVSS v2 Base Score: 7.7 | Impact Score: 10 | Exploitability Score: 5.1
VMScore: 775
Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 prior to 341.92, R352 prior to 354.35, and R358 prior to 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users to gain privileges via a commandline in a number 2 command, which is stored in the HKEY_LOCAL_MACHINE explorer Run registry key, a different vulnerability than CVE-2011-4784.

Vulnerable Product Search on Vulmon Subscribe to Product

nvidia gpu_driver

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=515 NVIDIA: Stereoscopic 3D Driver Service Arbitrary Run Key Creation Platform: Windows, NVIDIA Service Version 717135382 Class: Elevation of Privilege, Remote Code Execution Summary: The 3D Vision service nvSCPAPISvrexe installed as part of typical driver installati ...