{"api_version":"1","generated_at":"2026-07-23T07:38:30+00:00","cve":"CVE-2017-0314","urls":{"html":"https://cve.report/CVE-2017-0314","api":"https://cve.report/api/cve/CVE-2017-0314.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-0314","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-0314"},"summary":{"title":"CVE-2017-0314","description":"All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.","state":"PUBLISHED","assigner":"nvidia","published_at":"2017-02-15 23:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-119","Denial of Service, Escalation of Privileges"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4398","name":"http://nvidia.custhelp.com/app/answers/detail/a_id/4398","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Bulletin: NVIDIA GPU Display Driver contains multiple vulnerabilities in the kernel mode layer handler | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-0314","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-0314","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Nvidia Corporation","product":"Windows GPU Display Driver","version":"affected All","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"314","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"314","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"gpu_driver","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T13:03:56.528Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4398"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Windows GPU Display Driver","vendor":"Nvidia Corporation","versions":[{"status":"affected","version":"All"}]}],"datePublic":"2017-02-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges."}],"problemTypes":[{"descriptions":[{"description":"Denial of Service, Escalation of Privileges","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-02-15T22:57:01.000Z","orgId":"9576f279-3576-44b5-a4af-b9a8644b2de6","shortName":"nvidia"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4398"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@nvidia.com","ID":"CVE-2017-0314","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Windows GPU Display Driver","version":{"version_data":[{"version_value":"All"}]}}]},"vendor_name":"Nvidia Corporation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Denial of Service, Escalation of Privileges"}]}]},"references":{"reference_data":[{"name":"http://nvidia.custhelp.com/app/answers/detail/a_id/4398","refsource":"CONFIRM","url":"http://nvidia.custhelp.com/app/answers/detail/a_id/4398"}]}}}},"cveMetadata":{"assignerOrgId":"9576f279-3576-44b5-a4af-b9a8644b2de6","assignerShortName":"nvidia","cveId":"CVE-2017-0314","datePublished":"2017-02-15T23:00:00.000Z","dateReserved":"2016-11-23T00:00:00.000Z","dateUpdated":"2024-08-05T13:03:56.528Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-02-15 23:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-119","Denial of Service, Escalation of Privileges"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nvidia:gpu_driver:-:*:*:*:*:*:*:*","matchCriteriaId":"8F6B8C06-F379-49FB-B0F2-097752154708"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"314","Ordinal":"1","Title":"CVE-2017-0314","CVE":"CVE-2017-0314","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"314","Ordinal":"1","NoteData":"All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.","Type":"Description","Title":"CVE-2017-0314"},{"CveYear":"2017","CveId":"314","Ordinal":"2","NoteData":"2017-02-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"314","Ordinal":"3","NoteData":"2017-02-15","Type":"Other","Title":"Modified"}]}}}