CVE-2024-0107

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
08/08/2024
Last modified:
04/11/2025

Description

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 470 (including) 475.14 (excluding)
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 555 (including) 556.12 (excluding)
cpe:2.3:a:nvidia:geforce:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 470 (including) 475.14 (excluding)
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 535 (including) 538.78 (excluding)
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* 550 (including) 552.74 (excluding)
cpe:2.3:a:nvidia:quadro:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:rtx:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:tesla:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 13.12 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 14.0 (including) 16.7 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 17.0 (including) 17.3 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:cloud_gaming:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*