CVE-2020-5965
published 2020-06-25CVE-2020-5965: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.34%
26.0th percentile
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | geforce_firmware | >= 450 < 451.48 | 451.48 |
| nvidia | nvidia_gpu_display_driver | — | — |
| nvidia | nvs_firmware | >= 390 < 392.61 | 392.61 |
| nvidia | nvs_firmware | >= 418 < 426.78 | 426.78 |
| nvidia | nvs_firmware | >= 440 < 443.18 | 443.18 |
| nvidia | nvs_firmware | >= 450 < 451.48 | 451.48 |
| nvidia | quadro_firmware | >= 390 < 392.61 | 392.61 |
| nvidia | quadro_firmware | >= 418 < 426.78 | 426.78 |
| nvidia | quadro_firmware | >= 440 < 443.18 | 443.18 |
| nvidia | quadro_firmware | >= 450 < 451.48 | 451.48 |
| nvidia | tesla_firmware | >= 418 < 426.78 | 426.78 |
| nvidia | tesla_firmware | >= 440 < 443.18 | 443.18 |
| nvidia | tesla_firmware | >= 450 < 451.48 | 451.48 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
blogs_talos·2020-06-24·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
## Executive summary
The NVWGF2UMX_CFG.DLL driver contains a denial-of-service vulnerability that an attacker could use to disrupt processes over a virtual machine. An adversary could exploit this bug by
providing a specially crafted pixel shader over VMware guests and VMware hosts, leading to VMware to process crash on the host machine.
In accordance with our coordinated disclosure policy, Cisco Talos worked with NVIDIA and VMware to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
NVIDIA NVWGF2UMX_CFG.DLL shader functionality denial-of-service vulnerability (TALOS-2019-0971/CVE-2020-5965)
An exploitable denial of service vulnerability
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
blogs_talos·2020-06-24·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
## Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
## Executive summary
The NVWGF2UMX_CFG.DLL driver contains a denial-of-service vulnerability that an attacker could use to disrupt processes over a virtual machine. An adversary could exploit this bug by providing a specially crafted pixel shader over VMware guests and VMware hosts, leading to VMware to process crash on the host machine.
In accordance with our coordinated disclosure policy, Cisco Talos worked with NVIDIA and VMware to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
NVIDIA NVWGF2UMX_CFG.DLL shader functionality denial-of-service vulnerability (T
2020-06-25
Published