CVE-2017-6277: Input Validation
Published Sep 22, 2017
·Updated
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.
Affected Software
2 affected components
Nvidia GPU driver
Microsoft Windows
Event History
Sep 22, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6277?
CVE-2017-6277 has been classified as a moderate severity vulnerability.
2
What types of systems are affected by CVE-2017-6277?
CVE-2017-6277 affects systems running the NVIDIA Windows GPU Display Driver.
3
Can CVE-2017-6277 lead to a denial of service?
Yes, CVE-2017-6277 can result in denial of service due to improper validation of user input.
4
How do I fix CVE-2017-6277?
To fix CVE-2017-6277, update the NVIDIA GPU Display Driver to the latest version provided by NVIDIA.
5
Is user intervention required to exploit CVE-2017-6277?
Yes, user interaction is necessary as the vulnerability involves input from users to the driver.