QID 375689

Date Published: 2021-12-20

QID 375689: NVIDIA GeForce Experience Privilege Escalation Vulnerability

Nvidia GeForce Experience is the companion application to GeForce GTX graphics card. It keeps drivers up to date, automatically optimizes game settings.
CVE-2019-5702:NVIDIA GeForce Experience contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

Affected Versions:
prior to Nvidia GeForce Experience 3.23

QID Detection Logic

This QID checks for vulnerable verison of Nvidia Geforece Experience by checking the registry key.

Successful exploitation of these vulnerabilities can result denial of service or escalation of privileges.

  • CVSS V3 rated as Critical - 8.3 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Customers are advised to download Nvidia Geforce Experience 3.23 or later from here.
    Vendor References

    CVEs related to QID 375689

    Software Advisories
    Advisory ID Software Component Link
    Nvidia security bulletin Windows URL Logo www.geforce.com/geforce-experience/download