CVE-2021-1055
published 2021-01-08CVE-2021-1055: NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which…
PriorityP422medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.30%
22.2th percentile
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which improper access control may lead to denial of service and information disclosure.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | gpu_driver | >= 390 < 392.63 | 392.63 |
| nvidia | gpu_driver | >= 418 < 427.11 | 427.11 |
| nvidia | gpu_driver | >= 450 < 452.77 | 452.77 |
| nvidia | gpu_driver | >= 460 < 461.09 | 461.09 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Apache Log4j2 - Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-45046 [CRITICAL] Apache Log4j2 - Remote Code Injection
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Template:
id: CVE-2021-45046
info:
name: Apache Log4j2 - Remote Code Injection
author: ImNightmaree
severity: critical
description: Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Log4j2.
reference:
- https://securitylab.github.com/advisories/GHSL-2021-1054_GHSL-2021-1055_log4j2/
- https://twitter.com/marcioalm/status/147174077158165
No writeups or analysis indexed.
2021-01-08
Published