| Vulnerability Name: | CVE-2019-5670 (CCN-157947) | ||||||||||||
| Assigned: | 2019-02-27 | ||||||||||||
| Published: | 2019-02-27 | ||||||||||||
| Updated: | 2020-08-24 | ||||||||||||
| Summary: | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service, escalation of privileges, code execution or information disclosure. | ||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-119 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-5670 Source: CONFIRM Type: UNKNOWN http://support.lenovo.com/us/en/solutions/LEN-26250 Source: XF Type: UNKNOWN nvidia-cve20195670-code-exec(157947) Source: CCN Type: NVIDIA Security Bulletin Answer ID 4772 NVIDIA GPU Display Driver - February 2019 Source: CONFIRM Type: Patch, Vendor Advisory https://nvidia.custhelp.com/app/answers/detail/a_id/4772 Source: CCN Type: IBM Security Bulletin 876860 (Other xSeries) Vulnerabilities affect NVIDIA GPU Display Drivers for Linux and Windows | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||