Impact
The vulnerability is an out‑of‑bounds read in the firmware of NVIDIA GPU display drivers for both Windows and Linux. A successful exploit can allow an attacker to read memory beyond the intended buffer, leading to code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is a classic out‑of‑bounds read identified as CWE‑125.
Affected Systems
The affected products are NVIDIA GPU Display Drivers installed on GeForce, RTX, Quadro, NVS, and Tesla GPUs. This applies to any system running the driver on Windows or Linux where the firmware component is present.
Risk and Exploitability
The CVSS score is 6.7, indicating moderate severity. The EPSS score is not available, so the current risk period does not provide an estimated exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local: an attacker with access to a machine that can load or modify driver firmware could trigger the out‑of‑bounds read and potentially elevate privileges or execute code. No remote exploitation path is explicitly stated, but the impact domains include confidentiality, integrity, and availability.
OpenCVE Enrichment