CVE-2023-31019

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/11/2023
Last modified:
14/11/2023

Description

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 13.9 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 14.0 (including) 15.4 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 16.0 (including) 16.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools