Out-of-bounds read in NVIDIA vGPU Software and NVIDIA Windows GPU Display Driver - CVE-2022-31612
Published: August 9, 2022
Vulnerability identifier: #VU66206
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31612
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape. A local user can trigger an out-of-bounds read and execute arbitrary code on the target system with elevated privileges.
Affected software
NVIDIA vGPU Software
NVIDIA Windows GPU Display Driver
NVIDIA Windows GPU Display Driver
How to mitigate CVE-2022-31612
Install updates from vendor's website.
NVIDIA vGPU Software - addressed in versions 11.9, 13.4, 14.2
NVIDIA Windows GPU Display Driver - addressed in versions 473.81, 516.94
NVIDIA Windows GPU Display Driver - addressed in versions 473.81, 516.94