7.8
CWE
125
Advisory Published
Updated

CVE-2024-0107

First published: Thu Aug 08 2024(Updated: )

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Credit: psirt@nvidia.com

Affected SoftwareAffected VersionHow to fix
All of
Any of
NVIDIA GPU Display Driver>=470<475.14
NVIDIA GPU Display Driver>=555<556.12
NVIDIA GeForce
All of
Any of
NVIDIA GPU Display Driver>=470<475.14
NVIDIA GPU Display Driver>=535<538.78
NVIDIA GPU Display Driver>=550<552.74
Any of
NVIDIA Quadro
NVIDIA RTX
NVIDIA tesla
All of
Any of
NVIDIA vGPU Software<13.12
NVIDIA vGPU Software>=14.0<16.7
NVIDIA vGPU Software>=17.0<17.3
Microsoft Windows
All of
NVIDIA Cloud Gaming
Microsoft Windows

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-0107?

    CVE-2024-0107 has a high severity rating due to potential exploitation leading to code execution and privilege escalation.

  • How do I fix CVE-2024-0107?

    Fix CVE-2024-0107 by updating your NVIDIA GPU Display Driver to a version that is not affected by this vulnerability.

  • Who is affected by CVE-2024-0107?

    CVE-2024-0107 affects users of certain versions of the NVIDIA GPU Display Driver for Windows, specifically those between versions 470 and 475.14 and certain other specified ranges.

  • What are the potential impacts of CVE-2024-0107?

    Exploitation of CVE-2024-0107 can lead to code execution, denial of service, privilege escalation, and information disclosure.

  • Is there a workaround for CVE-2024-0107?

    There are no known workarounds for CVE-2024-0107; updating the driver is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203