First published: Thu Dec 23 2021(Updated: )
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GeForce Experience | <3.24.0.126 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23175 is a vulnerability in NVIDIA GeForce Experience that allows for escalation of privileges, information disclosure, data tampering, and denial of service.
CVE-2021-23175 can potentially allow unauthorized users to gain elevated privileges, access sensitive information, manipulate data, and disrupt the normal operation of the affected system.
NVIDIA GeForce Experience versions up to 3.24.0.126 are affected by CVE-2021-23175.
To mitigate CVE-2021-23175, it is recommended to update NVIDIA GeForce Experience to a version beyond 3.24.0.126, as this vulnerability has been patched in later releases.
You can find more information about CVE-2021-23175 and its impact on the NVIDIA GeForce Experience in the official NVIDIA security advisory: https://nvidia.custhelp.com/app/answers/detail/a_id/5295