Vulnerability Description
All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tamper with the extracted files, potentially leading to escalation of privileges via code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Gpu Driver | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/4398Vendor Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4398Vendor Advisory
FAQ
What is CVE-2017-0317?
CVE-2017-0317 is a vulnerability with a CVSS score of 7.5 (HIGH). All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tampe...
How severe is CVE-2017-0317?
CVE-2017-0317 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-0317?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Gpu Driver, Microsoft Windows.