CVE-2019-5676
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
10/05/2019
Last modified:
27/04/2022
Description
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* | 410 (including) | 412.36 (excluding) |
| cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* | 418 (including) | 425.51 (excluding) |
| cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* | 430 (including) | 430.64 (excluding) |
| cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:* | 3.19 (excluding) | |
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



