CVE-2021-1073

NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other web page is loaded in other tabs of the same browser. In this situation, the web page can get access to the token of the user login session, leading to the possibility that the user’s account is compromised. This may lead to the targeted user’s data being accessed, altered, or lost.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-668 NVD-CWE-noinfo

14 Jul 2021, 14:00

Type Values Removed Values Added
CVSS v2 : 6.8
v3 : 7.8
v2 : 5.1
v3 : 8.3

13 Jul 2021, 12:15

Type Values Removed Values Added
Summary NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability where, if a user clicks on a maliciously formatted link that opens the GeForce Experience login page in a new browser tab instead of the GeForce Experience application and enters their login information, the malicious site can get access to the token of the user login session. Such an attack may lead to these targeted users' data being accessed, altered, or lost. NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other web page is loaded in other tabs of the same browser. In this situation, the web page can get access to the token of the user login session, leading to the possibility that the user’s account is compromised. This may lead to the targeted user’s data being accessed, altered, or lost.

01 Jul 2021, 23:39

Type Values Removed Values Added
CWE CWE-668
References (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5199 - (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5199 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CPE cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

25 Jun 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-25 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-1073

Mitre link : CVE-2021-1073

CVE.ORG link : CVE-2021-1073


JSON object : View

Products Affected

microsoft

  • windows

nvidia

  • geforce_experience