CVE-2019-5684
published 2019-08-06CVE-2019-5684: NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds…
PriorityP356critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
5.42%
91.8th percentile
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | gpu_display_driver | — | — |
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684)
vendor_vmware·2019-08-02·CVSS 9.6
CVE-2019-5521 [CRITICAL] VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684)
VMSA-2019-0012: VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684)
| Advisory Severity | Important | CVSSv3 Range | 6.3-8.5 | Synopsis | VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684) | Issue Date | 2019-08-02 | Updated On | 2019-08-02 (Initial Advisory) | CVE(s) | CVE-2019-5521, CVE-2019-5684 VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation)
CVEs: CVE-2019-5521, CVE-2019-5684
Affected products: Fusion Pro, VMware ESXi, VMware Fusion, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
GHSA
GHSA-xr5v-45r7-33pq: NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of
ghsa_unreviewed·2022-05-24
CVE-2019-5684 [CRITICAL] CWE-787 GHSA-xr5v-45r7-33pq: NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
blogs_talos·2019-08-05·CVSS 9.6
[CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
Piotr Bania of Cisco Talos discovered these vulnerabilities.
### Executive summary VMware ESXi, Workstation and Fusion are affected by an out-of-bounds write vulnerability that can be triggered using a specially crafted shader file. This vulnerability can be triggered from a VMware guest, affecting the VMware host, leading to a crash (denial-of-service) of the vmware-vmx.exe process on the host (TALOS-2019-0757).
However, when the host/guest systems are using an NVIDIA graphics card, the VMware denial-of-service can be turned into a code execution vulnerability (leading to a VM escape), because of an
additional security issue present in NVIDIA's Windows GPU Display Driver (TALOS-2019-0779).
Moreover, two out-of-bounds write vulnerabilities that could lead to arbitrary code execution ha
Talos
Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
blogs_talos·2019-08-05·CVSS 9.6
[CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
## Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
Piotr Bania of Cisco Talos discovered these vulnerabilities.
## Executive summary VMware ESXi, Workstation and Fusion are affected by an out-of-bounds write vulnerability that can be triggered using a specially crafted shader file. This vulnerability can be triggered from a VMware guest, affecting the VMware host, leading to a crash (denial-of-service) of the vmware-vmx.exe process on the host (TALOS-2019-0757).
However, when the host/guest systems are using an NVIDIA graphics card, the VMware denial-of-service can be turned into a code execution vulnerability (leading to a VM escape), because of an
additional security issue present in NVIDIA's Windows GPU Disp
http://www.vmware.com/security/advisories/VMSA-2019-0012.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/4841https://support.lenovo.com/us/en/product_security/LEN-28096https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0779http://www.vmware.com/security/advisories/VMSA-2019-0012.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/4841https://support.lenovo.com/us/en/product_security/LEN-28096https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0779
2019-08-06
Published