CVE-2021-1092

NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.
References
Link Resource
https://nvidia.custhelp.com/app/answers/detail/a_id/5211 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*

History

31 Jul 2021, 00:17

Type Values Removed Values Added
CPE cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
References (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5211 - (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5211 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 3.6
v3 : 7.1
CWE CWE-269

22 Jul 2021, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-22 05:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-1092

Mitre link : CVE-2021-1092

CVE.ORG link : CVE-2021-1092


JSON object : View

Products Affected

nvidia

  • gpu_display_driver
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')