Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2015-1170

Overview

Vulnerability Score 7.2 7.2
CVE Id CVE-2015-1170
Last Modified 11 May 2015 10:03:06
Published 06 Mar 2015 06:59:02
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2015-1170

Summary

The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client impersonation levels when performing a "kernel administrator check," which allows local users to gain administrator privileges via unspecified API calls.

Vulnerable Systems

Application

  • Nvidia Gpu Driver R304 309.07

  • Nvidia Gpu Driver R340 341.43

  • Nvidia Gpu Driver R343 345.19

  • Nvidia Gpu Driver R346 347.51


References

CONFIRM - http://nvidia.custhelp.com/app/answers/detail/a_id/3634

HP - HPSBHF03271

SECTRACK - 1032013

HP - SSRT101950


Last Updated: 27 May 2016 11:08:00