First published: Tue Nov 08 2016(Updated: )
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100009a where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Driver | >=340<342.00 | |
Nvidia Gpu Driver | >=375<375.63 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8810 has a high severity rating due to the potential for privilege escalation in NVIDIA graphics drivers.
To fix CVE-2016-8810, update your NVIDIA GPU Display Driver to version 342.00 or later if using R340, or version 375.63 or later if using R375.
CVE-2016-8810 affects NVIDIA Quadro, NVS, and GeForce products with specific driver versions on Windows.
The main issue with CVE-2016-8810 is that it allows an attacker to pass a value to the driver without proper validation, leading to potential exploitation.
Microsoft Windows itself is not vulnerable due to CVE-2016-8810, but the affected NVIDIA drivers running on it are.