{"api_version":"1","generated_at":"2026-07-23T20:58:19+00:00","cve":"CVE-2021-1117","urls":{"html":"https://cve.report/CVE-2021-1117","api":"https://cve.report/api/cve/CVE-2021-1117.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-1117","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-1117"},"summary":{"title":"CVE-2021-1117","description":"Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.","state":"PUBLIC","assigner":"psirt@nvidia.com","published_at":"2021-10-27 21:15:00","updated_at":"2021-11-04 17:25:00"},"problem_types":["CWE-129"],"metrics":[],"references":[{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5230","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/5230","refsource":"CONFIRM","tags":[],"title":"Security Bulletin: NVIDIA GPU Display Driver - October 2021 | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-1117","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-1117","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"gpu_display_driver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-1117","qid":"376042","title":"NVIDIA GPU Display Driver Multiple Vulnerabilities (November 2021)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@nvidia.com","ID":"CVE-2021-1117","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"NVIDIA GPU Display Driver","version":{"version_data":[{"version_value":"All GPU Driver versions"}]}}]},"vendor_name":"NVIDIA"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service."}]},"impact":{"cvss":{"baseScore":4.7,"baseSeverity":"Medium","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-129: Improper Validation of Array Index"}]}]},"references":{"reference_data":[{"name":"https://nvidia.custhelp.com/app/answers/detail/a_id/5230","refsource":"CONFIRM","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5230"}]}},"nvd":{"publishedDate":"2021-10-27 21:15:00","lastModifiedDate":"2021-11-04 17:25:00","problem_types":["CWE-129"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:N/A:P","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":1.9},"severity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*","versionStartIncluding":"390","versionEndExcluding":"392.68","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*","versionStartIncluding":"470","versionEndExcluding":"472.39","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*","versionStartIncluding":"460","versionEndExcluding":"463.15","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*","versionStartIncluding":"495","versionEndExcluding":"496.49","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"1117","Ordinal":"191130","Title":"CVE-2021-1117","CVE":"CVE-2021-1117","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"1117","Ordinal":"1","NoteData":"Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"1117","Ordinal":"2","NoteData":"2021-10-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"1117","Ordinal":"3","NoteData":"2021-10-27","Type":"Other","Title":"Modified"}]}}}