First published: Fri Dec 30 2022(Updated: )
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | <11.11 | |
NVIDIA Virtual GPU | >=13.0<13.6 | |
NVIDIA Virtual GPU | >=14.0<14.4 | |
Microsoft Windows | ||
Nvidia Cloud Gaming | <527.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42266 is a vulnerability in the NVIDIA GPU Display Driver for Windows that allows an unprivileged regular user to expose sensitive information to an unauthorized actor.
CVE-2022-42266 has a severity score of 3.3, which is considered medium.
CVE-2022-42266 affects NVIDIA Virtual GPU versions up to 11.11 and versions between 13.0 and 13.6, exposing sensitive information to unauthorized actors.
No, Microsoft Windows is not vulnerable to CVE-2022-42266.
You can find more information about CVE-2022-42266 at the following link: [link](https://nvidia.custhelp.com/app/answers/detail/a_id/5415)