First published: Thu Jun 25 2020(Updated: )
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, in which a NULL pointer is dereferenced, leading to denial of service or potential escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver | >=390<392.61 | |
NVIDIA GPU Display Driver | >=418<426.78 | |
NVIDIA GPU Display Driver | >=440<443.18 | |
NVIDIA GPU Display Driver | >=450<451.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5966 has a high severity level due to its potential for denial of service and privilege escalation.
To fix CVE-2020-5966, users should update their NVIDIA GPU Display Driver to the latest version provided by NVIDIA.
CVE-2020-5966 is caused by a NULL pointer dereference in the kernel mode layer of the NVIDIA Windows GPU Display Driver.
CVE-2020-5966 affects all versions of the NVIDIA GPU Display Driver prior to the latest fix, including versions between 390-392.61, 418-426.78, 440-443.18, and 450-451.48.
CVE-2020-5966 primarily leads to local denial of service or privilege escalation, rather than remote exploitation.