First published: Tue Nov 24 2015(Updated: )
Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to gain privileges via a Trojan horse application, as demonstrated by C:\Program.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU kernel driver | >=340<341.92 | |
NVIDIA GPU kernel driver | >=352<354.35 | |
NVIDIA GPU kernel driver | >=358<358.87 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7866 is considered a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2015-7866, update the NVIDIA GPU graphics driver to version 341.92 or later, 354.35 or later, or 358.87 or later.
Local users on systems running vulnerable versions of the NVIDIA GPU graphics driver are impacted by CVE-2015-7866.
The potential impact of CVE-2015-7866 is that local users can exploit the vulnerability to gain elevated privileges.
CVE-2015-7866 affects NVIDIA GPU drivers versions prior to 341.92, 354.35, and 358.87.