QID 375727

Date Published: 2021-07-28

QID 375727: NVIDIA GPU Display Driver Multiple Vulnerabilities (January 2021)

NVIDIA has released a software security update for NVIDIA GPU Display Driver. This update addresses issues that may lead to denial of service, escalation of privileges, data tampering, or information disclosure.

Affected versions:
GeForce All versions prior to 461.09
NVIDIA RTX/Quadro, NVS All versions prior to 461.09
NVIDIA RTX/Quadro, NVS All versions prior to 452.77
NVIDIA RTX/Quadro, NVS All versions prior to 392.63
Tesla All versions prior to 461.09
Tesla All versions prior to 452.77
Tesla All versions prior to 427.11
QID detection logic (authenticated):
The QID checks for vulnerable versions of nvcpl.dll.

Successful exploitation by a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.

  • CVSS V3 rated as Critical - 8.4 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to download the fixes from NVIDIA Driver Downloads page.

    Software Advisories
    Advisory ID Software Component Link
    5142 URL Logo nvidia.custhelp.com/app/answers/detail/a_id/5142