The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client impersonation levels when performing a "kernel administrator check," which allows local users to gain administrator privileges via unspecified API calls.
2015-03-06T23:59:02.263
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nvidia | gpu_driver_r304 | ≤ 309.07 | Yes |
Application | nvidia | gpu_driver_r340 | ≤ 341.43 | Yes |
Application | nvidia | gpu_driver_r343 | ≤ 345.19 | Yes |
Application | nvidia | gpu_driver_r346 | ≤ 347.51 | Yes |