First published: Tue Nov 08 2016(Updated: )
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GeForce Experience | <=- | |
NVIDIA GeForce 910M | ||
NVIDIA GeForce 920M | ||
NVIDIA GeForce 920MX | ||
NVIDIA GeForce 930M | ||
NVIDIA GeForce 930MX | ||
NVIDIA GeForce 940M | ||
NVIDIA GeForce 940MX | ||
NVIDIA GeForce 945M | ||
NVIDIA GeForce GT 710 | ||
NVIDIA GeForce GT 730 | ||
NVIDIA GeForce GTX 1050 | ||
NVIDIA GeForce GTX 1060 | ||
NVIDIA GeForce GTX 1070 | ||
NVIDIA GeForce GTX 1080 | ||
Nvidia GeForce GTX 950M | ||
Nvidia GeForce GTX 960M Firmware | ||
NVIDIA GeForce GTX 965M | ||
NVIDIA NVS 310 | ||
NVIDIA NVS 315 | ||
NVIDIA | ||
NVIDIA | ||
Nvidia Quadro K1200 | ||
NVIDIA Quadro K420 | ||
NVIDIA Quadro K620 | ||
Nvidia Quadro M1000M | ||
NVIDIA Quadro M2000 | ||
NVIDIA Quadro M2000M | ||
NVIDIA Quadro M3000M | ||
NVIDIA Quadro M4000 | ||
NVIDIA Quadro M4000M | ||
NVIDIA Quadro M5000 | ||
NVIDIA Quadro M5000M | ||
NVIDIA Quadro M500M | ||
NVIDIA Quadro M5500 | ||
NVIDIA Quadro M6000 | ||
NVIDIA Quadro M600M | ||
NVIDIA Quadro P5000 | ||
NVIDIA Quadro P6000 | ||
NVIDIA Titan X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8812 is rated as a high severity vulnerability due to its ability to allow stack buffer overflow causing a potential system compromise.
To fix CVE-2016-8812, you should update NVIDIA GeForce Experience to version GFE 2.11.4.125 or later, or GFE 3.1.0.52 or later.
CVE-2016-8812 affects NVIDIA GeForce Experience R340 before version 2.11.4.125 and R375 before version 3.1.0.52.
No, CVE-2016-8812 specifically impacts the NVIDIA GeForce Experience software rather than specific graphics card models.
If CVE-2016-8812 is exploited, it could lead to a stack buffer overflow, which may allow an attacker to execute arbitrary code on the system.