MEDIUM · 6.7

CVE-2019-5676

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as...

Vulnerability Description

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NvidiaGpu Display Driver>= 410, < 412.36
NvidiaGeforce Experience< 3.19
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-5676?

CVE-2019-5676 is a vulnerability with a CVSS score of 6.7 (MEDIUM). NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as...

How severe is CVE-2019-5676?

CVE-2019-5676 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-5676?

Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Gpu Display Driver, Nvidia Geforce Experience, Microsoft Windows.