Impact
NVIDIA GPU Display Driver for Windows contains a kernel mode vulnerability that allows an unprivileged local user to supply an untrusted pointer, which the driver dereferences without validation. This flaw can lead to code execution in kernel space, denying service, escalating privileges, disclosing information, and tampering with data. The vulnerability is classified as CWE‑119, indicating an unsafe memory reference or buffer overflow during pointer handling.
Affected Systems
The affected products are NVIDIA GPU Display Drivers for Windows across the GeForce, RTX, Quadro, NVS, Tesla, and Virtual GPU Manager series. No specific driver versions are listed as affected, so any unpatched installation of these drivers on Windows systems is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity vulnerability. EPSS data is unavailable, and the vulnerability is not reported in CISA’s KEV catalog. Based on the description, the likely attack vector is a local, unprivileged user. Successful exploitation would provide kernel‑level execution and privilege escalation, making this issue critical for systems with local users authorized to load or use NVIDIA drivers.
OpenCVE Enrichment