First published: Tue Nov 08 2016(Updated: )
For the NVIDIA Quadro, NVS, and GeForce products, there is a Remote Desktop denial of service. A successful exploit of a vulnerable system will result in a kernel null pointer dereference, causing a blue screen crash.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Driver | >=340<341.96 | |
Nvidia Gpu Driver | >=352.0<354.99 | |
Nvidia Gpu Driver | >=361<362.77 | |
Nvidia Gpu Driver | >=367<368.39 | |
NVIDIA GeForce 910m | ||
NVIDIA GeForce 920M | ||
NVIDIA GeForce 920mx | ||
NVIDIA GeForce 930m | ||
NVIDIA GeForce 930mx | ||
NVIDIA GeForce 940m | ||
NVIDIA GeForce 940mx | ||
NVIDIA GeForce 945M | ||
NVIDIA GeForce GT 710 | ||
NVIDIA GeForce GT 730 | ||
NVIDIA GeForce GTX 1050 | ||
NVIDIA GeForce GTX 1060 | ||
NVIDIA GeForce GTX 1070 | ||
NVIDIA geforce gtx 1080 | ||
Nvidia GeForce GTX 950M | ||
Nvidia GeForce GTX 960M Firmware | ||
NVIDIA GeForce GTX 965M | ||
NVIDIA NVS 310 | ||
NVIDIA NVS 315 | ||
NVIDIA NVS 510 | ||
NVIDIA NVS 810 | ||
Nvidia Quadro K1200 | ||
NVIDIA Quadro K420 | ||
Nvidia Quadro K620 | ||
Nvidia Quadro M1000M | ||
NVIDIA Quadro M2000 | ||
NVIDIA Quadro M2000M | ||
NVIDIA Quadro M3000M | ||
NVIDIA Quadro M4000 | ||
NVIDIA Quadro M4000M | ||
NVIDIA Quadro M5000 | ||
NVIDIA Quadro M5000M | ||
NVIDIA quadro m500m | ||
NVIDIA Quadro M5500 | ||
NVIDIA Quadro M6000 | ||
NVIDIA Quadro M600M | ||
NVIDIA Quadro P5000 | ||
NVIDIA Quadro P6000 | ||
NVIDIA Titan X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4959 is classified as a high severity vulnerability due to its potential to cause a denial of service through a kernel null pointer dereference.
To mitigate CVE-2016-4959, update your NVIDIA GPU driver to a version that is higher than 368.39 or follow any specific patches provided by NVIDIA.
Successful exploitation of CVE-2016-4959 can lead to a system crash or blue screen, resulting in disruption of service.
CVE-2016-4959 affects various NVIDIA Quadro, NVS, and GeForce products with specific driver versions within the specified range.
Currently, disabling Remote Desktop functionality can serve as a temporary workaround for CVE-2016-4959 until a driver update is applied.