CVE-2020-5958Untrusted Search Path in Nvidia Geforce Experience

Severity
7.8HIGHNVD
EPSS
0.1%
top 65.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11
Latest updateMay 24

Description

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDnvidia/tesla_firmware440440.33.01
NVDnvidia/quadro_firmware390392.59+3
NVDnvidia/geforce_experience440442.50

🔴Vulnerability Details

2
GHSA
GHSA-9jww-fm9p-j95x: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system2022-05-24
CVEList
CVE-2020-5958: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system2020-03-11

💥Exploits & PoCs

1
Exploit-DB
libupnp 1.6.18 - Stack-based buffer overflow (DoS)2020-11-27
CVE-2020-5958 — Untrusted Search Path in Nvidia | cvebase