CVE-2016-7385: Buffer Overflow
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x700010d where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7385?
CVE-2016-7385 has been assigned a high severity rating due to potential privilege escalation vulnerabilities.
How do I fix CVE-2016-7385?
To address CVE-2016-7385, you should update the NVIDIA GPU driver to version 342.00 or above and also to version 375.63 or above.
What products are affected by CVE-2016-7385?
CVE-2016-7385 affects various NVIDIA Quadro, NVS, and GeForce products running earlier versions of the NVIDIA Windows GPU Display Driver.
What type of vulnerability is CVE-2016-7385?
CVE-2016-7385 is classified as a privilege escalation vulnerability within the kernel mode layer of the NVIDIA GPU driver.
What is the exploit target of CVE-2016-7385?
CVE-2016-7385 targets the kernel mode driver nvlddmkm.sys, where user input is improperly validated.