CVE-2013-0111
daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Affected
- nvidia/driver
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/957036US Government Resource
- http://www.nvidia.com/object/product-security.htmlVendor Advisory
- http://www.kb.cert.org/vuls/id/957036US Government Resource
- http://www.nvidia.com/object/product-security.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.