First published: Wed Apr 21 2021(Updated: )
NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver | >=390<392.65 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1074 is classified as a high severity vulnerability due to the potential for local unprivileged access leading to unauthorized file replacement.
To fix CVE-2021-1074, update the NVIDIA GPU Display Driver to a version above 392.65.
Users of the NVIDIA GPU Display Driver for Windows versions between 390 and 392.65 are affected by CVE-2021-1074.
CVE-2021-1074 is a security vulnerability in the installer of the NVIDIA GPU Display Driver that allows resource replacement by an attacker.
No, CVE-2021-1074 requires local unprivileged system access for exploitation.