2024-12-08 03:06:42 +00:00

129 lines
4.1 KiB
JSON

{
"id": "CVE-2019-5701",
"sourceIdentifier": "psirt@nvidia.com",
"published": "2019-11-09T02:15:12.083",
"lastModified": "2024-11-21T04:45:22.390",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service, information disclosure, or escalation of privileges through code execution."
},
{
"lang": "es",
"value": "NVIDIA GeForce Experience, todas las versiones anteriores a la versi\u00f3n 3.20.0.118, contiene una vulnerabilidad cuando GameStream est\u00e1 habilitado en el que un atacante con acceso al sistema local puede cargar las DLL del controlador de gr\u00e1ficos Intel sin validar la ruta o la firma (tambi\u00e9n conocida como plantaci\u00f3n binaria o precarga de DLL ataque), que puede conducir a la denegaci\u00f3n de servicio, divulgaci\u00f3n de informaci\u00f3n o escalada de privilegios a trav\u00e9s de la ejecuci\u00f3n del c\u00f3digo."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"baseScore": 6.2,
"accessVector": "LOCAL",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 1.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*",
"versionEndExcluding": "3.20.0.118",
"matchCriteriaId": "86CE60CF-70D1-4715-9FCD-06705DD82690"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-011.md",
"source": "psirt@nvidia.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/4860",
"source": "psirt@nvidia.com",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-011.md",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/4860",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}