Impact
The vulnerability is an out‑of‑bounds write in the Windows and Linux GPU display driver firmware. If an attacker can trigger the flaw, the firmware may accept data beyond allocated buffers, potentially allowing arbitrary memory corruption. This could result in code execution, privilege escalation, data tampering, or denial of service. The weakness is mapped to CWE-787.
Affected Systems
The flaw affects NVIDIA GPU products across several families, including GeForce, RTX, Quadro, NVS, and Tesla. All devices that use the affected GPU display driver on Windows or Linux are vulnerable, regardless of name or model. The description does not specify particular driver or firmware versions, so any installation of the current driver that contains the vulnerable code is at risk.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the KEV catalog. Because the flaw occurs in firmware, a successful exploit would likely require the attacker to deliver a crafted payload via the driver’s interface or have local access to the device. The potential impact is significant, but exploitation is confined to systems with the vulnerable drivers. The risk is higher on machines that allow direct GPU interaction such as gaming or GPU‑accelerated workflows.
OpenCVE Enrichment