Several NVidia PC Gaming Product Vulnerabilities

English

Several NVidia PC gaming product vulnerabilities, affecting Windows users.

Nvidia has issued fixes for high-severity flaws in two popular gaming products, including its graphics driver for Windows and GeForce Experience.

Several NVidia PC gaming product vulnerabilities, affecting Windows users.

The flaws can be exploited to launch an array of malicious attacks, from denial-of-service efforts (DoS) to escalation of privileges.

The majority of the high-severity flaws are in the Windows GPU Display Driver, Nvidia’s graphics driver used in devices targeted to enthusiast gamers.

This is the software component that enables the device’s operating system and programs to use its high-level graphics hardware.

The driver has three high-severity flaws (CVE‑2019‑5690, CVE‑2019‑5691, CVE‑2019‑5692), which all stem from the kernel mode layer handler component of the driver, Nvidia said on Wednesday.

Kernel mode is generally reserved for the lowest-level, most trusted functions of the operating system; in this case, the layer handler (nvlddmkm.sys) for the DxgkDdiEscape interface within the kernel mode has an array of glitches.

These issues include the handler not validating the size of an input buffer (CVE‑2019‑5690), derefencing a NULL pointer (CVE‑2019‑5691) and using untrusted input when calculating an array index (CVE‑2019‑5692).

All of these issues could enable escalation of privileges or DoS.

These flaws are strikingly similar to high-severity vulnerabilities reported by Nvidia in May 2019, which also existed in the DxgkDdiEscape interface within the kernel mode layer of the driver.

Those flaws could have led to information disclosure, escalation of privileges and DoS in impacted Windows gaming devices.

In total the graphics driver has nine vulnerabilities, including three high-severity and six medium-severity flaws.

Featured Sponsors

Games For Linux

Windows has always been the preferred platform for gaming, but after STEAM's interest in Linux more game developers are making their games natively available for Linux.

Disclaimer

All information on this website is published in good faith and for general educational purposes and for use in safe testing environments only. While linuxexperten.com strives to make the information on this site as accurate as possible, linuxexperten.com does not warrant its completeness, reliability and accuracy.

We are not responsible for any losses or damages associated with the use of our website. While we strive to provide only links to useful websites, we have no control over the content of these sites and links to other sites do not constitute a recommendation for all content contained on these websites.

 

Site Information

This is a professional review site that receives compensation from the companies whose products reviewed. Each service or product are thoroughly tested and given high marks if considered to be the very best. Independently owned and the opinions expressed here are no one elses.

 

Limited Time Offers

This time Linux Foundation has a really great offer, you wouldn't want to miss out on !

It is valid between: 10/17/2019 - 12/31/2019

Get a FREE Dell Chromebook 11 with qualifying Linux Foundation instructor-led course purchase!