CVE-2016-8808: High severity nvidia gpu kernel driver vulnerability
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000d5 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8808?
CVE-2016-8808 has a medium severity rating due to the potential for privilege escalation.
How do I fix CVE-2016-8808?
To fix CVE-2016-8808, update the NVIDIA GPU Display Driver to version 342.00 or later for R340 and version 375.63 or later for R375.
What systems are affected by CVE-2016-8808?
CVE-2016-8808 affects NVIDIA Quadro, NVS, and GeForce products with specific versions of the NVIDIA Windows GPU Display Driver.
Is CVE-2016-8808 exploitable?
Yes, CVE-2016-8808 is exploitable as it allows unvalidated user input to be processed by the driver.
What component of the system is impacted by CVE-2016-8808?
CVE-2016-8808 specifically impacts the kernel mode layer handler in the nvlddmkm.sys file.