CVE-2017-0316

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/10/2017
Last modified:
20/04/2025

Description

In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:* 3.0 (including) 3.10.0.55 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*