ZeroHour

CVE-2017-0317

CVSS 3.0
7.5 high
EPSS
<1%p35
Published
()
Modified
Description

All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tamper with the extracted files, potentially leading to escalation of privileges via code execution.

Vendors
nvidia
Products
gpu driver
Weakness
CWE-732
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.