First published: Tue Apr 12 2016(Updated: )
The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information from kernel memory, cause a denial of service (crash), or possibly gain privileges via unspecified vectors, which trigger uninitialized or out-of-bounds memory access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Driver R340 | =431.61 | |
Nvidia Gpu Driver R352 | =353.82 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2557 has a critical severity rating due to its potential to allow local users to exploit kernel memory.
To fix CVE-2016-2557, upgrade to NVIDIA GPU graphics driver versions R340 341.95 or higher, or R352 354.74 or higher.
CVE-2016-2557 affects local users with access to systems running vulnerable versions of NVIDIA GPU drivers.
CVE-2016-2557 can lead to sensitive information disclosure, denial of service, or privilege escalation.
While updating the driver is the primary mitigation for CVE-2016-2557, ensuring proper user access controls can also reduce risk.