CVE-2021-1074: High severity nvidia gpu display driver vulnerability
NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1074?
CVE-2021-1074 is classified as a high severity vulnerability due to the potential for local unprivileged access leading to unauthorized file replacement.
How do I fix CVE-2021-1074?
To fix CVE-2021-1074, update the NVIDIA GPU Display Driver to a version above 392.65.
Who is affected by CVE-2021-1074?
Users of the NVIDIA GPU Display Driver for Windows versions between 390 and 392.65 are affected by CVE-2021-1074.
What type of vulnerability is CVE-2021-1074?
CVE-2021-1074 is a security vulnerability in the installer of the NVIDIA GPU Display Driver that allows resource replacement by an attacker.
Can remote users exploit CVE-2021-1074?
No, CVE-2021-1074 requires local unprivileged system access for exploitation.