Vulnerability: Local Privilege Escalation via NVIDIA GPU Display Driver Installer

Vulnerability: Local Privilege Escalation via NVIDIA GPU Display Driver Installer

CVE-2021-1074 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.

Learn more about our User Device Pen Test.