CVE-2021-1074

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/04/2021
Last modified:
21/07/2022

Description

NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 390 (including) 392.65 (excluding)


References to Advisories, Solutions, and Tools