Denial of service in nVidia products - CVE-2016-8812

 

Denial of service in nVidia products - CVE-2016-8812

Published: November 1, 2016


Vulnerability identifier: #VU1128
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8812
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to cause D0S condition or obtain elevated privileges on the target system.
The weakness exists in the kernel mode layer (nvstreamkms.sys). By specially crafted executable paths a local attacker can trigger a stack buffer overflow, leading to a denial of service or escalation of privileges.
Successful exploitation of the vulnerability may result in denial of service or privilege escalation.


Affected software

NVIDIA App (formerly GeForce Experience)
Quadro
NVS
NVIDIA Windows GPU Display Driver

How to mitigate CVE-2016-8812

Update to version 2.11.4.125, 3.1.0.52.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins