7.8
CVE-2023-31017
- EPSS 0.02%
- Published 02.11.2023 19:15:41
- Last modified 21.11.2024 08:01:15
- Source psirt@nvidia.com
- Teams watchlist Login
- Open Login
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
Data is provided by the National Vulnerability Database (NVD)
Nvidia ≫ Virtual Gpu Version < 13.9
Nvidia ≫ Virtual Gpu Version >= 14.0 < 15.4
Nvidia ≫ Virtual Gpu Version >= 16.0 < 16.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.044 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
psirt@nvidia.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.