First published: Mon Apr 08 2013(Updated: )
nvSCPAPISvr.exe in the NVIDIA Stereoscopic 3D Driver service, as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Driver | <=307.00 | |
Nvidia Driver | =310.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0110 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
CVE-2013-0110 allows local users to gain elevated privileges on affected systems, which could lead to unauthorized access or control.
To fix CVE-2013-0110, update to the NVIDIA driver version 311.00 or later.
NVIDIA drivers before version 307.78 and version 310.00 are affected by CVE-2013-0110.
CVE-2013-0110 cannot be exploited remotely; it requires local access to the affected machine.