Impact
The vulnerability resides in the kernel mode layer of NVIDIA's GPU Display Drivers for Windows and Linux, allowing an attacker to perform an out‑of‑bounds write. This defect can be exploited to execute arbitrary code, potentially leading to denial of service, privilege escalation, information disclosure, and data tampering. flaw is associated with CWE‑787, which represents data or control flow conditions enabling out‑of‑bounds writes.
Affected Systems
Affected products include NVIDIA GeForce, RTX, Quadro, NVS, and Tesla GPUs. No specific version details were supplied by the CNA, so any build running the vulnerable driver could be susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium to high severity, and the vulnerability is not listed in CISA's KEV catalog. Since EPSS data is not available, the likelihood of exploitation in the wild remains uncertain. The attack likely requires local system presence to interact with the vulnerable driver, making it more relevant to privileged or local attackers. If exploited, it would compromise confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment