First published: Wed Oct 27 2021(Updated: )
Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GPU Display Driver | >=390<392.68 | |
NVIDIA GPU Display Driver | >=460<463.15 | |
NVIDIA GPU Display Driver | >=470<472.39 | |
NVIDIA GPU Display Driver | >=495<496.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1117 has a severity rating of medium, indicating that it may lead to denial of service under certain conditions.
To mitigate CVE-2021-1117, update the NVIDIA GPU Display Driver to a version that is not affected by this vulnerability.
CVE-2021-1117 affects Windows systems running specific versions of the NVIDIA GPU Display Driver.
CVE-2021-1117 can be exploited through local unprivileged system access by an attacker capable of configuring the driver improperly.
Exploitation of CVE-2021-1117 can result in a denial of service, disrupting the functionality of the affected systems.