CVE-2026-24191
published 2026-05-26CVE-2026-24191: NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this…
PriorityP340high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.14%
3.6th percentile
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | gpu_display_driver | >= 535 < 535.309.01 | 535.309.01 |
| nvidia | gpu_display_driver | >= 535 < 539.72 | 539.72 |
| nvidia | gpu_display_driver | >= 580 < 580.159.03 | 580.159.03 |
| nvidia | gpu_display_driver | >= 580 < 582.53 | 582.53 |
| nvidia | gpu_display_driver | >= 595 < 595.36 | 595.36 |
| nvidia | gpu_display_driver | >= 595 < 595.71.05 | 595.71.05 |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA GeForce on Windows Display Driver toctou (Nessus ID 316513)
vuldb·2026-05-26·CVSS 7.8
CVE-2026-24191 [HIGH] NVIDIA GeForce on Windows Display Driver toctou (Nessus ID 316513)
A vulnerability classified as critical has been found in NVIDIA GeForce, RTX, Quadro, NVS, Tesla, Guest driver and Virtual GPU Manager on Windows. This affects an unknown part of the component Display Driver. Performing a manipulation results in time-of-check time-of-use.
This vulnerability was named CVE-2026-24191. The attack needs to be approached locally. There is no available exploit.
GHSA
GHSA-2439-7mhv-329q: NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue
ghsa_unreviewed·2026-05-26
CVE-2026-24191 [HIGH] CWE-367 GHSA-2439-7mhv-329q: NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-26
Published