First published: Tue May 17 2022(Updated: )
NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Gpu Display Driver | ||
NVIDIA Virtual GPU | >=11.0<11.8 | |
NVIDIA Virtual GPU | >=13.0<13.3 | |
NVIDIA Virtual GPU | =14.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28182 is a vulnerability in the NVIDIA GPU Display Driver for Windows, specifically in the DirectX11 user mode driver (nvwgf2um/x.dll).
The severity of CVE-2022-28182 is high, with a CVSS score of 8.5.
CVE-2022-28182 allows an unauthorized attacker on the network to cause an out-of-bounds write in the NVIDIA GPU Display Driver, potentially leading to code execution, denial of service, or escalation of privileges.
NVIDIA GPU Display Driver for Windows versions, NVIDIA Virtual GPU versions 11.0 to 11.8 and 13.0 to 13.3, and NVIDIA Virtual GPU version 14.0 are affected by CVE-2022-28182.
To mitigate CVE-2022-28182, it is recommended to update to the latest version of the NVIDIA GPU Display Driver for Windows and NVIDIA Virtual GPU.