CVE-2016-2556
The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows improperly allows access to restricted functionality, which allows local users to gain privileges via unspecified…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows improperly allows access to restricted functionality, which allows local users to gain privileges via unspecified vectors.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- nvidia/gpu driver r340 · nvidia/gpu driver r352
- Source
- cve@mitre.org
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/4059Vendor Advisory
- https://support.lenovo.com/us/en/product_security/len_5551Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4059Vendor Advisory
- https://support.lenovo.com/us/en/product_security/len_5551Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.