{"api_version":"1","generated_at":"2026-07-23T04:20:13+00:00","cve":"CVE-2016-8809","urls":{"html":"https://cve.report/CVE-2016-8809","api":"https://cve.report/api/cve/CVE-2016-8809.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8809","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8809"},"summary":{"title":"CVE-2016-8809","description":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.","state":"PUBLISHED","assigner":"nvidia","published_at":"2016-11-08 20:59:22","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-20","CWE-264","Denial of Service"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://support.lenovo.com/us/en/solutions/LEN-10822","name":"https://support.lenovo.com/us/en/solutions/LEN-10822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Solutions len 10822","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247","name":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Vulnerabilities in NVIDIA Windows GPU Display Driver and NVIDIA GeForce Experience | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93992","name":"http://www.securityfocus.com/bid/93992","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"NVIDIA GPU Display Driver CVE-2016-8809 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/40664/","name":"https://www.exploit-db.com/exploits/40664/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"NVIDIA Driver - Incorrect Bounds Check in Escape 0x70001b2 - Windows dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8809","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8809","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Quadro, NVS, and GeForce (all versions)","version":"affected Quadro, NVS, and GeForce (all versions)","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"gpu_driver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:35:00.918Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"40664","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/40664/"},{"name":"93992","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/93992"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.lenovo.com/us/en/solutions/LEN-10822"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Quadro, NVS, and GeForce (all versions)","vendor":"n/a","versions":[{"status":"affected","version":"Quadro, NVS, and GeForce (all versions)"}]}],"datePublic":"2016-11-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges."}],"problemTypes":[{"descriptions":[{"description":"Denial of Service","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-02T09:57:01.000Z","orgId":"9576f279-3576-44b5-a4af-b9a8644b2de6","shortName":"nvidia"},"references":[{"name":"40664","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/40664/"},{"name":"93992","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/93992"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.lenovo.com/us/en/solutions/LEN-10822"},{"tags":["x_refsource_CONFIRM"],"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@nvidia.com","ID":"CVE-2016-8809","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Quadro, NVS, and GeForce (all versions)","version":{"version_data":[{"version_value":"Quadro, NVS, and GeForce (all versions)"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Denial of Service"}]}]},"references":{"reference_data":[{"name":"40664","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/40664/"},{"name":"93992","refsource":"BID","url":"http://www.securityfocus.com/bid/93992"},{"name":"https://support.lenovo.com/us/en/solutions/LEN-10822","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/solutions/LEN-10822"},{"name":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247","refsource":"CONFIRM","url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247"}]}}}},"cveMetadata":{"assignerOrgId":"9576f279-3576-44b5-a4af-b9a8644b2de6","assignerShortName":"nvidia","cveId":"CVE-2016-8809","datePublished":"2016-11-08T20:37:00.000Z","dateReserved":"2016-10-18T00:00:00.000Z","dateUpdated":"2024-08-06T02:35:00.918Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-11-08 20:59:22","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-20","CWE-264","Denial of Service"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:*","versionStartIncluding":"340","versionEndExcluding":"342.00","matchCriteriaId":"61D45869-80B6-43BA-B8A9-F62F094192AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:*","versionStartIncluding":"375","versionEndExcluding":"375.63","matchCriteriaId":"0AE75B76-5DC6-4700-AAF5-80B409287BB1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8809","Ordinal":"1","Title":"CVE-2016-8809","CVE":"CVE-2016-8809","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8809","Ordinal":"1","NoteData":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.","Type":"Description","Title":"CVE-2016-8809"},{"CveYear":"2016","CveId":"8809","Ordinal":"2","NoteData":"2016-11-08","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8809","Ordinal":"3","NoteData":"2017-09-02","Type":"Other","Title":"Modified"}]}}}