Impact
The vulnerability is an out‑of‑bounds write in the kernel mode layer of NVIDIA’s GPU display driver for Windows and Linux. An attacker who can trigger the flaw may be able to execute arbitrary code, crash the system, or gain higher privileges. The impact potentially extends to code execution, denial of service, privilege escalation, information disclosure, and data tampering, which together could compromise confidentiality, integrity, and availability.
Affected Systems
Affected products include NVIDIA GeForce, RTX, Quadro, NVS, Tesla, and associated guest drivers on both Windows and Linux platforms. No specific version information is available from the CNA; the vulnerability is presumed to affect all current driver releases until patches are applied.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. EPSS data is not available, but the lack of a KEV listing does not negate the high risk posed. The attack likely requires the victim to be a local user or a program with GPU access, allowing a local privilege escalation path. Given the kernel‑mode nature of the flaw, exploitation would be feasible without needing network exposure if an attacker can supply malicious GPU commands or payloads.
OpenCVE Enrichment