CVE-2021-1075
Published Apr 21, 2021
Last updated 3 years ago
Overview
- Description
- NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the program dereferences a pointer that contains a location for memory that is no longer valid, which may lead to code execution, denial of service, or escalation of privileges. Attacker does not have any control over the information and may conduct limited data modification.
- Source
- psirt@nvidia.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.3
- Impact score
- 4.7
- Exploitability score
- 2
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5.6
- Impact score
- 7.8
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:C
Weaknesses
- nvd@nist.gov
- CWE-476
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "22DC6378-9844-4247-8395-563EF075D0B2", "versionEndExcluding": "427.33", "versionStartIncluding": "418" }, { "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "3876CD3B-354A-4FE5-A528-A4B135F300C6", "versionEndExcluding": "452.96", "versionStartIncluding": "450" }, { "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "DF304158-67E3-4F9A-86D8-226626211F26", "versionEndExcluding": "462.31", "versionStartIncluding": "460" }, { "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "6F6BA69D-0332-4D95-867E-C03892F2091B", "versionEndExcluding": "466.11", "versionStartIncluding": "465" } ], "operator": "OR" } ] } ]