Vulnerability Name: | CVE-2013-0109 (CCN-82766) | ||||||||
Assigned: | 2012-12-06 | ||||||||
Published: | 2013-02-22 | ||||||||
Updated: | 2013-04-09 | ||||||||
Summary: | The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.9 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-0109 Source: CCN Type: SA52546 NVIDIA Graphics Drivers for Windows Unspecified Privilege Escalation Vulnerability Source: CCN Type: US-CERT VU#957036 NVIDIA Windows video card drivers contain multiple vulnerabilities Source: CERT-VN Type: US Government Resource VU#957036 Source: CCN Type: NVIDIA Web site NVIDIA Product Security Source: CONFIRM Type: Patch, Vendor Advisory http://www.nvidia.com/object/product-security.html Source: CCN Type: BID-58459 NVIDIA Graphics Driver for Windows CVE-2013-0109 Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN nvidia-graphics-priv-escalation(82766) Source: CCN Type: Packet Storm Security [12-17-2013] Nvidia (nvsvc) Display Driver Service Local Privilege Escalation Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [12-17-2013] Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-30-2018] Nvidia (nvsvc) Display Driver Service Local Privilege Escalation | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |