7.3
CVE-2021-1075
- EPSS 0.05%
- Published 21.04.2021 23:15:07
- Last modified 21.11.2024 05:43:32
- Source psirt@nvidia.com
- Teams watchlist Login
- Open Login
NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the program dereferences a pointer that contains a location for memory that is no longer valid, which may lead to code execution, denial of service, or escalation of privileges. Attacker does not have any control over the information and may conduct limited data modification.
Data is provided by the National Vulnerability Database (NVD)
Nvidia ≫ Gpu Display Driver SwPlatformwindows Version >= 418 < 427.33
Nvidia ≫ Gpu Display Driver SwPlatformwindows Version >= 450 < 452.96
Nvidia ≫ Gpu Display Driver SwPlatformwindows Version >= 460 < 462.31
Nvidia ≫ Gpu Display Driver SwPlatformwindows Version >= 465 < 466.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.116 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.3 | 2 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
|
nvd@nist.gov | 5.6 | 3.9 | 7.8 |
AV:L/AC:L/Au:N/C:N/I:P/A:C
|
psirt@nvidia.com | 7.3 | 2 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.