Privilege Escalation in nVidia products - CVE-2016-5852
Published: October 5, 2016 / Updated: October 6, 2016
Vulnerability identifier: #VU760
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5852
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to obtain elevated privileges on the target system.
The vulnerability exists due to improper input validation in GFE GameStream and NVTray Plugin. A local user can bypass security restrictions and obtain elevated privileges on the system.
Successful exploitation of this vulnerability will allow the local attacker to obtain elevated privileges on vulnerable system and cause arbitrary code execution.Affected software
NVS
Quandro
NVIDIA Windows GPU Display Driver
Quandro
NVIDIA Windows GPU Display Driver
How to mitigate CVE-2016-5852
NVIDIA has released software updates at the following link: Geforce, NVS, or Quadro