SB2019080646 - Input validation error in NVIDIA Windows GPU Display Driver
Published: August 6, 2019 Updated: August 8, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-5686)
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the kernel mode layer (nvlddmkm.sys) for DxgkDdiEscape when the software uses an API function or data structure with no guarantee, that properties are valid. A local authenticated attacker can perform a denial of service attack on the target system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.