CVE-2016-7386

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to leaking of kernel memory contents to user space through an uninitialized buffer.
References
Link Resource
http://nvidia.custhelp.com/app/answers/detail/a_id/4247 Patch Vendor Advisory
http://www.securityfocus.com/bid/93982 Third Party Advisory VDB Entry
https://support.lenovo.com/us/en/solutions/LEN-10822 Third Party Advisory
https://www.exploit-db.com/exploits/40656/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-11-08 20:59

Updated : 2024-02-04 18:53


NVD link : CVE-2016-7386

Mitre link : CVE-2016-7386

CVE.ORG link : CVE-2016-7386


JSON object : View

Products Affected

microsoft

  • windows

nvidia

  • gpu_driver
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor