NVIDIA GPU Graphics Crash Vulnerability

Summary

Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or possibly gain privileges

Credit:

Details

Vulnerable Systems:
 * NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87

Immune Systems:
 * NVIDIA GPU graphics driver R340 after 341.92, R352 after 354.35, and R358 after 358.87

This advisory relates to a security vulnerability in the NVAPI support layer of NVIDIA GPU graphics drivers. The NVAPI support layer is an NVIDIA exported API layer to support augmented system functionality to application software. This report also details an advisory regarding integer overflow issues in the underlying kernel mode driver.

CVE Information:
CVE-2015-8328

Disclosure Timeline:
Original release date: 11/24/2015
Last revised: 11/25/2015

Categories: News