CVE-2022-34671
published 2022-12-30CVE-2022-34671: NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may…
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.39%
69.0th percentile
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | gpu_display_driver | >= 450 < 454.02 | 454.02 |
| nvidia | gpu_display_driver | >= 470 < 474.14 | 474.14 |
| nvidia | gpu_display_driver | >= 510 < 514.08 | 514.08 |
| nvidia | gpu_display_driver | >= 515 < 517.88 | 517.88 |
| nvidia | gpu_display_driver | 515 – 517.88 | — |
| nvidia | gpu_display_driver | >= 525 < 527.27 | 527.27 |
| nvidia | gpu_display_driver | >= 525 < 527.41 | 527.41 |
| nvidia | gpu_display_driver | >= 525 < 526.98 | 526.98 |
| nvidia | nvidia_gpu_display_driver_for_windows | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Three vulnerabilities in NVIDIA graphics driver could cause memory corruption
blogs_talos·2023-08-23·CVSS 8.5
CVE-2022-34671 [HIGH] Three vulnerabilities in NVIDIA graphics driver could cause memory corruption
Piotr Bania of Cisco Talos discovered the vulnerabilities mentioned in this post.
Cisco Talos recently disclosed three vulnerabilities in the shader functionality of the NVIDIA D3D10 driver that works with NVIDIA’s graphics cards.
The driver is vulnerable to memory corruption if an adversary sends a specially crafted shader packer, which can lead to a memory corruption problem in the driver.
All three issues, identified as TALOS-2023-1719 (CVE-2022-34671), TALOS-2023-1720 (CVE-2022-34671) and TALOS-2023-1721 (CVE-2022-34671), have a CVSS severity rating of 8.5 out of 10.
An attacker could exploit these vulnerabilities from guest machines running virtualization environments (such as VMware, QEMU and VirtualBox) to perform a guest-to-host escape, as we’ve illustrated with previous vulner
Talos
Three vulnerabilities in NVIDIA graphics driver could cause memory corruption
blogs_talos·2023-08-23·CVSS 8.5
[HIGH] Three vulnerabilities in NVIDIA graphics driver could cause memory corruption
## Three vulnerabilities in NVIDIA graphics driver could cause memory corruption
Piotr Bania of Cisco Talos discovered the vulnerabilities mentioned in this post.
Cisco Talos recently disclosed three vulnerabilities in the shader functionality of the NVIDIA D3D10 driver that works with NVIDIA’s graphics cards.
The driver is vulnerable to memory corruption if an adversary sends a specially crafted shader packer, which can lead to a memory corruption problem in the driver.
All three issues, identified as TALOS-2023-1719 (CVE-2022-34671), TALOS-2023-1720 (CVE-2022-34671) and TALOS-2023-1721 (CVE-2022-34671), have a CVSS severity rating of 8.5 out of 10.
An attacker could exploit these vulnerabilities from guest machines running virtualization environments (such as VMware, QEMU and Virtua
Talos
Vulnerability Spotlight: NVIDIA driver memory corruption vulnerabilities discovered
blogs_talos·2022-12-06·CVSS 8.5
[HIGH] Vulnerability Spotlight: NVIDIA driver memory corruption vulnerabilities discovered
## Vulnerability Spotlight: NVIDIA driver memory corruption vulnerabilities discovered
Cisco Talos recently discovered two memory corruption vulnerabilities in shader functionality of an NVIDIA driver.
NVIDIA Graphics drivers are software for NVIDIA Graphics GPU installed on the PC. They are used to communicate between the operating system and the GPU device. This software is required in most cases for the hardware device to function properly.
Two exploitable memory corruption vulnerabilities exist in the NVIDIA graphics driver: TALOS-2022-1603 (CVE-2022-34671) and TALOS-2022-1604 (CVE-2022-34671). An attacker can use a malicious shader file to trigger these vulnerabilities. These vulnerabilities could also potentially be triggered from guest operating systems running in virtualization
Talos
Vulnerability Spotlight: NVIDIA driver memory corruption vulnerabilities discovered
blogs_talos·2022-12-06·CVSS 8.5
CVE-2022-34671 [HIGH] Vulnerability Spotlight: NVIDIA driver memory corruption vulnerabilities discovered
Cisco Talos recently discovered two memory corruption vulnerabilities in shader functionality of an NVIDIA driver.
NVIDIA Graphics drivers are software for NVIDIA Graphics GPU installed on the PC. They are used to communicate between the operating system and the GPU device. This software is required in most cases for the hardware device to function properly.
Two exploitable memory corruption vulnerabilities exist in the NVIDIA graphics driver: TALOS-2022-1603 (CVE-2022-34671) and TALOS-2022-1604 (CVE-2022-34671). An attacker can use a malicious shader file to trigger these vulnerabilities. These vulnerabilities could also potentially be triggered from guest operating systems running in virtualization environments (ie. VMware, qemu, VirtualBox, etc.) and can lead to so-called guest-to-hos
Checkpoint
5th December – Threat Intelligence Report
blogs_checkpoint·2022-12-05
CVE-2022-4262 5th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Cyber criminals who breached Australian Medibank’s systems have released another batch of data onto the dark web, claiming that the files contain all data harvested in the former heist that impacted 9.7 million customers in October 2022. Medibank has confirmed the data breach.
Colombian healthcare provider Keralty, opera
https://nvidia.custhelp.com/app/answers/detail/a_id/5415https://nvidia.custhelp.com/app/answers/detail/a_id/5468https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1719https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1720https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1721https://nvidia.custhelp.com/app/answers/detail/a_id/5415https://nvidia.custhelp.com/app/answers/detail/a_id/5468https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1719https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1720https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1721
2022-12-30
Published