CVE-2019-5676

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
10/05/2019
Last modified:
27/04/2022

Description

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 410 (including) 412.36 (excluding)
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 418 (including) 425.51 (excluding)
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 430 (including) 430.64 (excluding)
cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:* 3.19 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*