{"api_version":"1","generated_at":"2026-07-23T05:46:01+00:00","cve":"CVE-2016-8811","urls":{"html":"https://cve.report/CVE-2016-8811","api":"https://cve.report/api/cve/CVE-2016-8811.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8811","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8811"},"summary":{"title":"CVE-2016-8811","description":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.","state":"PUBLISHED","assigner":"nvidia","published_at":"2016-11-08 20:59:24","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","Denial of Service"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://support.lenovo.com/us/en/solutions/LEN-10822","name":"https://support.lenovo.com/us/en/solutions/LEN-10822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Solutions len 10822","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93988","name":"http://www.securityfocus.com/bid/93988","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"NVIDIA GPU Driver CVE-2016-8811 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/40662/","name":"https://www.exploit-db.com/exploits/40662/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"NVIDIA Driver - No Bounds Checking in Escape 0x7000170 - Windows dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247","name":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Vulnerabilities in NVIDIA Windows GPU Display Driver and NVIDIA GeForce Experience | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8811","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8811","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Quadro, NVS, and GeForce (all versions)","version":"affected Quadro, NVS, and GeForce (all versions)","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8811","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"gpu_driver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:35:01.137Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"40662","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/40662/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.lenovo.com/us/en/solutions/LEN-10822"},{"name":"93988","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/93988"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Quadro, NVS, and GeForce (all versions)","vendor":"n/a","versions":[{"status":"affected","version":"Quadro, NVS, and GeForce (all versions)"}]}],"datePublic":"2016-11-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges."}],"problemTypes":[{"descriptions":[{"description":"Denial of Service","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-02T09:57:01.000Z","orgId":"9576f279-3576-44b5-a4af-b9a8644b2de6","shortName":"nvidia"},"references":[{"name":"40662","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/40662/"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.lenovo.com/us/en/solutions/LEN-10822"},{"name":"93988","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/93988"},{"tags":["x_refsource_CONFIRM"],"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@nvidia.com","ID":"CVE-2016-8811","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Quadro, NVS, and GeForce (all versions)","version":{"version_data":[{"version_value":"Quadro, NVS, and GeForce (all versions)"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Denial of Service"}]}]},"references":{"reference_data":[{"name":"40662","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/40662/"},{"name":"https://support.lenovo.com/us/en/solutions/LEN-10822","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/solutions/LEN-10822"},{"name":"93988","refsource":"BID","url":"http://www.securityfocus.com/bid/93988"},{"name":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247","refsource":"CONFIRM","url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4247"}]}}}},"cveMetadata":{"assignerOrgId":"9576f279-3576-44b5-a4af-b9a8644b2de6","assignerShortName":"nvidia","cveId":"CVE-2016-8811","datePublished":"2016-11-08T20:37:00.000Z","dateReserved":"2016-10-18T00:00:00.000Z","dateUpdated":"2024-08-06T02:35:01.137Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-11-08 20:59:24","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","Denial of Service"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:*","versionStartIncluding":"340","versionEndExcluding":"342.00","matchCriteriaId":"61D45869-80B6-43BA-B8A9-F62F094192AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:*","versionStartIncluding":"375","versionEndExcluding":"375.63","matchCriteriaId":"0AE75B76-5DC6-4700-AAF5-80B409287BB1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8811","Ordinal":"1","Title":"CVE-2016-8811","CVE":"CVE-2016-8811","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8811","Ordinal":"1","NoteData":"For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.","Type":"Description","Title":"CVE-2016-8811"},{"CveYear":"2016","CveId":"8811","Ordinal":"2","NoteData":"2016-11-08","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8811","Ordinal":"3","NoteData":"2017-09-02","Type":"Other","Title":"Modified"}]}}}