Insecure DLL loading in NVIDIA vGPU Software and NVIDIA Windows GPU Display Driver - CVE-2021-1089
Published: July 20, 2021
Vulnerability identifier: #VU55036
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1089
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner in nvidia-smi. A local user can place a malicious .dll file on the system and execute arbitrary code with elevated privileges.
Affected software
NVIDIA vGPU Software
NVIDIA Windows GPU Display Driver
NVIDIA Windows GPU Display Driver
How to mitigate CVE-2021-1089
Install updates from vendor's website.
NVIDIA vGPU Software - addressed in versions 8.8, 11.5, 12.3
NVIDIA Windows GPU Display Driver - addressed in versions 392.67, 427.48, 453.10, 462.96, 471.41
NVIDIA Windows GPU Display Driver - addressed in versions 392.67, 427.48, 453.10, 462.96, 471.41