{"api_version":"1","generated_at":"2026-07-23T10:00:16+00:00","cve":"CVE-2019-5689","urls":{"html":"https://cve.report/CVE-2019-5689","api":"https://cve.report/api/cve/CVE-2019-5689.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5689","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5689"},"summary":{"title":"CVE-2019-5689","description":"NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a user with local system access can craft input that may allow malicious files to be downloaded and saved. This behavior may lead to code execution, denial of service, or information disclosure.","state":"PUBLIC","assigner":"psirt@nvidia.com","published_at":"2019-11-09 02:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4860","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4860","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: NVIDIA GeForce Experience - November 2019 | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5689","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5689","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"5689","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"geforce_experience","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5689","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"geforce_experience","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-5689","ASSIGNER":"psirt@nvidia.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"NVIDIA","product":{"product_data":[{"product_name":"NVIDIA GeForce Experience","version":{"version_data":[{"version_value":"All versions prior to 3.20.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"code execution, denial of service, or information disclosure"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4860","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4860"}]},"description":{"description_data":[{"lang":"eng","value":"NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a user with local system access can craft input that may allow malicious files to be downloaded and saved. This behavior may lead to code execution, denial of service, or information disclosure."}]}},"nvd":{"publishedDate":"2019-11-09 02:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*","versionEndExcluding":"3.20.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5689","Ordinal":"143310","Title":"CVE-2019-5689","CVE":"CVE-2019-5689","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5689","Ordinal":"1","NoteData":"NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a user with local system access can craft input that may allow malicious files to be downloaded and saved. This behavior may lead to code execution, denial of service, or information disclosure.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5689","Ordinal":"2","NoteData":"2019-11-08","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5689","Ordinal":"3","NoteData":"2019-11-08","Type":"Other","Title":"Modified"}]}}}