First published: Fri Oct 23 2020(Updated: )
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GeForce Experience | <3.20.5.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-5977 is high with a CVSS score of 7.8.
CVE-2020-5977 is a vulnerability in NVIDIA GeForce Experience versions prior to 3.20.5.70, where an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
All versions prior to 3.20.5.70 of NVIDIA GeForce Experience are affected by CVE-2020-5977.
CVE-2020-5977 can be exploited by using an uncontrolled search path to load a malicious node module, potentially leading to code execution, denial of service, escalation of privileges, and information disclosure.
Yes, upgrading NVIDIA GeForce Experience to version 3.20.5.70 or later will fix the vulnerability.