CVE-2016-8427
published 2017-01-12CVE-2016-8427: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the…
PriorityP339high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.62%
73.4th percentile
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-31799885. References: N-CVE-2016-8427.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| msrc | microsoft_excel_viewer_2007_service_pack_3 | — | — |
| msrc | microsoft_office_2016_for_mac | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_compatibility_pack_service_pack_3 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | microsoft_powerpoint_viewer_2007 | — | — |
| msrc | office_365_proplus_for_32-bit_systems | — | — |
| msrc | office_365_proplus_for_64-bit_systems | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_itanium-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Graphics Components Information Disclosure Vulnerability
vendor_msrc·2018-10-09·CVSS 4.7
CVE-2018-8427 [MEDIUM] Microsoft Graphics Components Information Disclosure Vulnerability
Microsoft Graphics Components Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information that could be useful for further exploitation.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.
FAQ: What is Office 365 ProPlus?
Office 365 ProPlus is the same product formerly be referred to as Microsoft Office 2016 Click-to-Run (C2R). The name has been updated in this guide to reflect Microsoft’s branding.
FAQ: What type of information could be disclosed by
Android
CVE-2016-8427: Android Security Bulletin 2017-01-01
CVE: CVE-2016-8427
Severity: CRITICAL
References: A-31799885*
N-CVE-2016-8427
vendor_android·2017-01-01·CVSS 7.8
CVE-2016-8427 [HIGH] CVE-2016-8427: Android Security Bulletin 2017-01-01
CVE: CVE-2016-8427
Severity: CRITICAL
References: A-31799885*
N-CVE-2016-8427
Android Security Bulletin 2017-01-01
CVE: CVE-2016-8427
Severity: CRITICAL
References: A-31799885*
N-CVE-2016-8427
GHSA
GHSA-4rf9-x8g3-5q7c: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the conte
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2016-8427 [HIGH] GHSA-4rf9-x8g3-5q7c: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the conte
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-31799885. References: N-CVE-2016-8427.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://nvidia.custhelp.com/app/answers/detail/a_id/4561http://www.securityfocus.com/bid/95231https://source.android.com/security/bulletin/2017-01-01.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4561http://www.securityfocus.com/bid/95231https://source.android.com/security/bulletin/2017-01-01.html
2017-01-12
Published