First published: Mon Nov 18 2019(Updated: )
NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpumodeswitch | <2019-11 | |
NVIDIA NVFlash | <5.588.0 | |
Nvidia Nvuflash | <5.588.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5688 has a medium severity rating, allowing authenticated users to exploit it with administrative privileges.
To fix CVE-2019-5688, update the NVIDIA NVFlash and NVUFlash tools to version 5.588.0 or higher, and the GPUModeSwitch Tool to a version released after November 2019.
Authenticated users with administrative privileges running affected versions of NVIDIA NVFlash, NVUFlash, or GPUModeSwitch on Windows are vulnerable to CVE-2019-5688.
CVE-2019-5688 affects devices using NVIDIA NVFlash, NVUFlash, and GPUModeSwitch tools that run prior to the specified fixed versions.
An attacker exploiting CVE-2019-5688 can gain unauthorized access to device memory and registers, potentially leading to further system compromise.