{"api_version":"1","generated_at":"2026-07-23T11:20:05+00:00","cve":"CVE-2019-5675","urls":{"html":"https://cve.report/CVE-2019-5675","api":"https://cve.report/api/cve/CVE-2019-5675.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5675","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5675"},"summary":{"title":"CVE-2019-5675","description":"NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes, which may lead to denial of service, escalation of privileges, or information disclosure.","state":"PUBLIC","assigner":"psirt@nvidia.com","published_at":"2019-05-10 21:29:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-662"],"metrics":[],"references":[{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4797","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4797","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: NVIDIA GPU Display Driver - May 2019 | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5675","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5675","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"5675","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"gpu_driver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5675","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"gpu_driver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-5675","qid":"376247","title":"NVIDIA GPU Display Driver Multiple Vulnerabilities (May 2019)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-5675","ASSIGNER":"psirt@nvidia.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"NVIDIA","product":{"product_data":[{"product_name":"NVIDIA GPU Display Driver","version":{"version_data":[{"version_value":"All"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"denial of service, escalation of privileges, or information disclosure"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4797","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4797"}]},"description":{"description_data":[{"lang":"eng","value":"NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes, which may lead to denial of service, escalation of privileges, or information disclosure."}]}},"nvd":{"publishedDate":"2019-05-10 21:29:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-662"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:windows:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5675","Ordinal":"143296","Title":"CVE-2019-5675","CVE":"CVE-2019-5675","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5675","Ordinal":"1","NoteData":"NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes, which may lead to denial of service, escalation of privileges, or information disclosure.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5675","Ordinal":"2","NoteData":"2019-05-10","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5675","Ordinal":"3","NoteData":"2019-05-10","Type":"Other","Title":"Modified"}]}}}