1554565467657.jpg
(144Кб, 990x716)
Пять опасных уязвимостей затрагивают все версии драйверов для массовых графических ускорителей GeForce (до 431.60). Самая серьёзная из них (CVE-2019-5683) с оценкой 8,8 балла позволяет потенциальному злоумышленнику выполнять код, вызывать отказ в обслуживании и устанавливать привилегии. Две другие уязвимости (CVE-2019-5684 и CVE-2019-5685) позволяют делать то же самое, но через DirectX. Проблема актуальна только для систем под управлением ОС Windows 7 и выше.
CVE‑2019‑5683 NVIDIA Windows GPU Display Driver contains a vulnerability in the user mode video driver trace logger component. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.
CVE‑2019‑5684 NVIDIA Windows GPU Display Driver contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.
CVE‑2019‑5685 NVIDIA Windows GPU Display Driver contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access to a shader local temporary array, which may lead to denial of service or code execution.
CVE‑2019‑5686 NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software uses an API function or data structure in a way that relies on properties that are not always guaranteed to be valid, which may lead to denial of service.
CVE‑2019‑5687 NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default permissions for an object exposes it to an unintended actor, which may lead to information disclosure or denial of service.
https://trashbox.ru/link/2019-08-05-nvidia-drivers-security-update
GeForce Affected Versions All R430 versions prior to 431.60 Updated Version 431.60