SB2017080101 - Multiple vulnerabilities in NVIDIA GPU Display Driver 



SB2017080101 - Multiple vulnerabilities in NVIDIA GPU Display Driver

Published: August 1, 2017

Security Bulletin ID SB2017080101
Severity
Low
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 secuirty vulnerabilities.


1) Privilege escalation (CVE-ID: CVE-2017-6251)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer handler due to improper permissions check. A local attacker can gain access to arbitrary physical system memory and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

2) Privilege escalation (CVE-ID: CVE-2017-6252)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer handler due to NULL pointer dereference. A local attacker can cause the system to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

3) Privilege escalation (CVE-ID: CVE-2017-6253)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape due to boundary error. A local attacker can cause the system to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

4) Privilege escalation (CVE-ID: CVE-2017-6254)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape due to improper validation of the pointer passed from a user to the driver. A local attacker can cause the system to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

5) Privilege escalation (CVE-ID: CVE-2017-6255)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape due to an error when handling user-supplied parameter. A local attacker can cause the system to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

6) Denial of service (CVE-ID: CVE-2017-6259)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the kernel mode layer helper function due to incorrect detection and recovery from an invalid state. A remote attacker can perform specific actions and cause the system to crash.

Successful exploitation of the vulnerability results in denial of service.

7) Privilege escalation (CVE-ID: CVE-2017-6257)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer handler due to NULL pointer dereference. A local attacker can cause the system to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

8) Privilege escalation (CVE-ID: CVE-2017-6256)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape due to improper input validation. A local attacker can pass specially crafted values to the driver cause the system to use it as the index to an array, trigger system crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

9) Denial of service (CVE-ID: CVE-2017-6260)

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape due to incorrect calculation of string length. A local attacker can cause the system to crash.

Successful exploitation of the vulnerability may result in denial of service.

Remediation

Install update from vendor's website.