CVE-2021-1117
published 2021-10-27CVE-2021-1117: Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.3th percentile
Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | gpu_display_driver | >= 390 < 392.68 | 392.68 |
| nvidia | gpu_display_driver | >= 460 < 463.15 | 463.15 |
| nvidia | gpu_display_driver | >= 470 < 472.39 | 472.39 |
| nvidia | gpu_display_driver | >= 495 < 496.49 | 496.49 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c663-86cm-fc8f: Windows contains a vulnerability in the kernel mode layer (nvlddmkm
ghsa_unreviewed·2022-05-24
CVE-2021-1117 [MEDIUM] CWE-129 GHSA-c663-86cm-fc8f: Windows contains a vulnerability in the kernel mode layer (nvlddmkm
Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.
SonicWall
CVE-2021-20051: SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of t
vendor_sonicwall·2022-05-04·CVSS 7.8
CVE-2021-20051 [HIGH] CWE-427 CVE-2021-20051: SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of t
CVE-2021-20051: SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-27
Published