First published: Thu Jul 22 2021(Updated: )
NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver | >=427.33<427.48 | |
NVIDIA GPU Display Driver | >=452.96<453.10 | |
NVIDIA GPU Display Driver | >=462.31<462.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1092 has been assigned a high severity rating due to the potential for an unprivileged attacker to overwrite privileged files and cause denial of service.
To address CVE-2021-1092, users should promptly update the NVIDIA GPU Display Driver to a version that is not affected by this vulnerability.
CVE-2021-1092 affects specific versions of NVIDIA GPU Display Driver between 427.33 and 427.48, 452.96 and 453.10, and 462.31 and 462.96.
CVE-2021-1092 can be exploited by an unprivileged attacker with access to the system.
CVE-2021-1092 may lead to denial of service by allowing attackers to overwrite critical files, potentially disrupting system functionality.