cve/2017/CVE-2017-0313.md

19 lines
943 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2017-0313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0313)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20GPU%20Display%20Driver&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Denial%20of%20Service%2C%20Escalation%20of%20Privileges&color=brighgreen)
### Description
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.
### POC
#### Reference
- http://nvidia.custhelp.com/app/answers/detail/a_id/4398
- https://www.exploit-db.com/exploits/41365/
#### Github
No PoCs found on GitHub currently.