7.2

CVE-2019-5676

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nvidia ≫ Gpu Display Driver SwPlatform windows Version >= 410 < 412.36
Nvidia ≫ Gpu Display Driver SwPlatform windows Version >= 418 < 425.51
Nvidia ≫ Gpu Display Driver SwPlatform windows Version >= 430 < 430.64
Nvidia ≫ Geforce Experience Version < 3.19
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.397
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://nvidia.custhelp.com/app/answers/detail/a_id/4797
Vendor Advisory
https://nvidia.custhelp.com/app/answers/detail/a_id/4806
Vendor Advisory
https://nvidia.custhelp.com/app/answers/detail/a_id/4841
Vendor Advisory
https://support.lenovo.com/us/en/product_security/LEN-27815
Third Party Advisory