7.8
CVSSv3

CVE-2016-7385

Published: 08/11/2016 Updated: 07/03/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 prior to 342.00 and R375 prior to 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x700010d where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

nvidia gpu_driver

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=894 The DxgkDdiEscape handler for 0x700010d accepts a user provided pointer as the destination for a memcpy call, without doing any checks on said pointer void __fastcall escape_700010D(NvMiniportDeviceContext* ctx, NvEscapeData *escape) { v8 = escape->unknown_2; ...