| Vulnerability Name: | CVE-2015-7866 (CCN-108166) | ||||||||||||
| Assigned: | 2015-11-18 | ||||||||||||
| Published: | 2015-11-18 | ||||||||||||
| Updated: | 2019-02-13 | ||||||||||||
| Summary: | Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to gain privileges via a Trojan horse application, as demonstrated by C:\Program.exe. CWE-428: Unquoted Search Path or Element | ||||||||||||
| CVSS v3 Severity: | 7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-7866 Source: CCN Type: NVIDIA Web site CVE-2015-7866: NVIDIA CONTROL PANEL UNQUOTED PATH Source: CONFIRM Type: Vendor Advisory http://nvidia.custhelp.com/app/answers/detail/a_id/3806/kw/security Source: SECTRACK Type: Third Party Advisory, VDB Entry 1034175 Source: XF Type: UNKNOWN nvidia-cve20157866-priv-esc(108166) Source: HP Type: Third Party Advisory HPSBHF03545 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||