First published: Tue Apr 20 2021(Updated: )
NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files are created using NT/System level permissions, which may lead to code execution, denial of service, or local privilege escalation. The attacker does not have control over the consequence of a modification nor would they be able to leak information as a direct result of the overwrite.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GeForce Experience | <3.22 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this NVIDIA GeForce Experience vulnerability is CVE-2021-1079.
The severity of CVE-2021-1079 is medium.
NVIDIA GeForce Experience versions prior to 3.22 are affected by CVE-2021-1079.
CVE-2021-1079 may lead to code execution, denial of service, or local privilege escalation.
To fix CVE-2021-1079, update NVIDIA GeForce Experience to version 3.22 or later.