Description
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local code execution via kernel mode pointer dereference
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Windows contains a kernel mode vulnerability that allows an unprivileged local user to supply an untrusted pointer, which the driver dereferences without validation. This flaw can lead to code execution in kernel space, denying service, escalating privileges, disclosing information, and tampering with data. The vulnerability is classified as CWE‑119, indicating an unsafe memory reference or buffer overflow during pointer handling.

Affected Systems

The affected products are NVIDIA GPU Display Drivers for Windows across the GeForce, RTX, Quadro, NVS, Tesla, and Virtual GPU Manager series. No specific driver versions are listed as affected, so any unpatched installation of these drivers on Windows systems is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 denotes a high severity vulnerability. EPSS data is unavailable, and the vulnerability is not reported in CISA’s KEV catalog. Based on the description, the likely attack vector is a local, unprivileged user. Successful exploitation would provide kernel‑level execution and privilege escalation, making this issue critical for systems with local users authorized to load or use NVIDIA drivers.

Generated by OpenCVE AI on September 30, 2026 at 18:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NVIDIA GPU Display Driver to the latest version that includes the pointer validation fix. If no patch is available, restrict local user access to NVIDIA driver operations by limiting administrator rights or disabling the driver for non‑admin accounts. Monitor system logs for kernel‑level errors and anomalous activity, and consider disabling untrusted applications from invoking the graphics stack until a patch is applied.

Generated by OpenCVE AI on September 30, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Kernel Mode Pointer Dereference in NVIDIA GPU Display Driver Allows Local Execution

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-119
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:51.660Z

Reserved: 2026-05-19T19:55:44.855Z

Link: CVE-2026-47550

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:26.106Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:22.937

Modified: 2026-09-30T18:18:27.627

Link: CVE-2026-47550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:00:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer