First published: Fri Oct 23 2020(Updated: )
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in its services in which a folder is created by nvcontainer.exe under normal user login with LOCAL_SYSTEM privileges which may lead to a denial of service or escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GeForce Experience | <3.20.5.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5978 is a vulnerability in NVIDIA GeForce Experience, all versions prior to 3.20.5.70, where a folder is created by nvcontainer.exe under normal user login with LOCAL_SYSTEM privileges, which may lead to a denial of service or escalation of privileges.
CVE-2020-5978 has a severity rating of 7.8 out of 10, indicating a high severity vulnerability.
NVIDIA GeForce Experience versions prior to 3.20.5.70 are affected by CVE-2020-5978.
CVE-2020-5978 can be exploited by creating a folder using nvcontainer.exe under normal user login with LOCAL_SYSTEM privileges.
Yes, the vulnerability can be fixed by updating NVIDIA GeForce Experience to version 3.20.5.70 or later.