CVE-2015-1170
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
06/03/2015
Last modified:
12/04/2025
Description
The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client impersonation levels when performing a "kernel administrator check," which allows local users to gain administrator privileges via unspecified API calls.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nvidia:gpu_driver_r304:*:*:*:*:*:*:*:* | 309.07 (including) | |
| cpe:2.3:a:nvidia:gpu_driver_r340:*:*:*:*:*:*:*:* | 341.43 (including) | |
| cpe:2.3:a:nvidia:gpu_driver_r343:*:*:*:*:*:*:*:* | 345.19 (including) | |
| cpe:2.3:a:nvidia:gpu_driver_r346:*:*:*:*:*:*:*:* | 347.51 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=142781493222653&w=2
- http://marc.info/?l=bugtraq&m=143013598825091&w=2
- http://marc.info/?l=bugtraq&m=143013598825091&w=2
- http://nvidia.custhelp.com/app/answers/detail/a_id/3634
- http://www.securitytracker.com/id/1032013
- https://support.lenovo.com/product_security/nvidia_windows_privilege
- https://support.lenovo.com/us/en/product_security/nvidia_windows_privilege
- http://marc.info/?l=bugtraq&m=142781493222653&w=2
- http://marc.info/?l=bugtraq&m=143013598825091&w=2
- http://marc.info/?l=bugtraq&m=143013598825091&w=2
- http://nvidia.custhelp.com/app/answers/detail/a_id/3634
- http://www.securitytracker.com/id/1032013
- https://support.lenovo.com/product_security/nvidia_windows_privilege
- https://support.lenovo.com/us/en/product_security/nvidia_windows_privilege



