Platform
nvidia
Component
nvidia-gpu-graphics-driver
CVE-2019-5666 is a security vulnerability affecting NVIDIA GPU Graphics Drivers. The vulnerability resides within the kernel mode layer (nvlddmkm.sys) and stems from improper validation of array indices during the create context command. This could lead to denial of service or privilege escalation. Affected versions include all NVIDIA GPU Graphics Drivers.
The impact of CVE-2019-5666 includes the potential for denial of service (DoS) and privilege escalation. A DoS condition could result in system crashes or instability, disrupting critical operations. Privilege escalation could allow an attacker to gain elevated privileges, potentially compromising the entire system. The vulnerability's location within the kernel mode driver makes it particularly concerning, as it can be exploited to bypass security controls at a low level.
CVE-2019-5666 was published on February 27, 2019. The CVSS severity score is pending evaluation. Public proof-of-concept (POC) code may exist, but its availability and ease of use are currently unknown. Monitor NVIDIA's security advisories and industry threat intelligence feeds for updates on exploitation activity.
Exploit Status
EPSS
0.04% (14% percentiel)
The primary mitigation for CVE-2019-5666 is to update to the latest available version of the NVIDIA GPU Graphics Driver. NVIDIA typically releases security updates to address these types of vulnerabilities. Until an update is available, consider limiting the use of graphics-intensive applications and monitoring system logs for any suspicious activity related to the NVIDIA GPU driver. Implement kernel-level security hardening measures to reduce the attack surface.
Actualice el controlador de gráficos NVIDIA a la última versión disponible desde el sitio web oficial de NVIDIA o a través del software GeForce Experience. Esto solucionará la vulnerabilidad en el controlador del modo kernel.
Kwetsbaarheidsanalyses en kritieke waarschuwingen direct in uw inbox.
It's a vulnerability in NVIDIA GPU Graphics Drivers allowing DoS or privilege escalation due to array index errors.
All versions of NVIDIA GPU Graphics Drivers are potentially affected.
Update to the latest NVIDIA GPU Graphics Driver.
Exploitation activity is currently unknown, but the potential exists.
Refer to NVIDIA's security advisories and the CVE entry for more details: https://cve.mitre.org/cgi-bin/cve/search?keyword=CVE-2019-5666
Upload je dependency-bestand en kom direct te weten of deze en andere CVEs jou raken.