CVE-2019-5688
Summary
| CVE | CVE-2019-5688 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-18 18:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Nvidia | Gpumodeswitch | All | All | All | All |
| Application | Nvidia | Gpumodeswitch | All | All | All | All |
| Application | Nvidia | Nvflash | All | All | All | All |
| Application | Nvidia | Nvflash | All | All | All | All |
| Application | Nvidia | Nvuflash | All | All | All | All |
| Application | Nvidia | Nvuflash | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: NVIDIA NVFlash, GPUModeSwitch Tool - November 2019 | NVIDIA | MISC | nvidia.custhelp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.