7.8
CVSSv3

CVE-2016-7384

Published: 08/11/2016 Updated: 07/03/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 prior to 342.00 and R375 prior to 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) where unchecked input/output lengths in UVMLiteController Device IO Control handling may lead to denial of service or potential escalation of privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

nvidia gpu_driver

Exploits

/* Source: bugschromiumorg/p/project-zero/issues/detail?id=880 The \\\UVMLiteController device is created by the nvlddmkmsys driver, and can be opened by any user The driver handles various control codes for this device, but there is no validation for the input/output buffer and their sizes In addition to potential overreads on the ...