7.8
CVE-2022-42267
- EPSS 0.07%
- Published 30.12.2022 23:15:11
- Last modified 21.11.2024 07:24:37
- Source psirt@nvidia.com
- Teams watchlist Login
- Open Login
NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
Data is provided by the National Vulnerability Database (NVD)
Nvidia ≫ Virtual Gpu Version < 11.11
Nvidia ≫ Virtual Gpu Version >= 13.0 < 13.6
Nvidia ≫ Virtual Gpu Version >= 14.0 < 14.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.232 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
psirt@nvidia.com | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.