Impact
An unprivileged user can trigger a use‑after‑free in the NVIDIA GPU Display Driver on Windows and Linux, a flaw identified as CWE‑416. The vulnerability can lead to arbitrary code execution at the kernel level, allowing the attacker to elevate privileges, tamper with data, crash the system or expose sensitive information. The impact is limited to the local machine, but once privilege escalation is achieved, full system compromise becomes possible.
Affected Systems
Affected NVIDIA products include GeForce, Guest driver, RTX, Quadro, NVS, and Tesla GPUs. No specific driver version numbers are listed in the advisory, so any installation of the NVIDIA GPU Display Driver prior to the published fix may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as High severity. EPSS data is unavailable, and the flaw is not yet cataloged in CISA KEV. The likely attack vector is local, requiring the attacker to have permissions to run code on the target machine, such as through a user‑level application that interacts with the GPU. Successful exploitation can grant kernel privileges, effectively compromising the entire host.
OpenCVE Enrichment