CVE-2015-5950

UnknownEPSS 0.36%

Last modified

CVE-2015-5950 is a vulnerability of currently unknown severity. The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.

Metrics

EPSS Probability
0.36%

28.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NvidiaGpu Driver<= 352.30
NvidiaDisplay Driver<= 352.09
NvidiaDisplay Driver304.108
NvidiaDisplay Driver304.119
NvidiaDisplay Driver304.121
NvidiaDisplay Driver304.123
NvidiaDisplay Driver304.125
NvidiaDisplay Driver352.21
NvidiaDisplay Driver352.30
NvidiaDisplay Driver<= 352.86
NvidiaDisplay Driver340.43
NvidiaDisplay Driver340.52
NvidiaDisplay Driver341.44
NvidiaDisplay Driver353.06

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-5950?
The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.
How severe is CVE-2015-5950?
Severity scoring for CVE-2015-5950 is pending analysis. The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2015-5950?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-5950?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST