CVE-2021-1052 — Improper Privilege Management in Nvidia GPU Driver
Severity
7.8HIGHNVD
EPSS
0.2%
top 57.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 8
Latest updateMay 24
Description
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
7GHSA▶
GHSA-4qmf-j7f2-r929: NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm↗2022-05-24
OSV▶
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.4, linux-hwe-5.8, linux-oracle update↗2021-01-21
OSV
▶
OSV▶
nvidia-graphics-drivers-390, nvidia-graphics-drivers-450, nvidia-graphics-drivers-460 vulnerabilities↗2021-01-11
OSV▶
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-hwe-5.8, linux-oem-5.6, linux-oracle, linux-oracle-5.4 vulnerabilities↗2021-01-11
📋Vendor Advisories
5Debian▶
CVE-2021-1052: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulner...↗2021