
Cloud Vulnerability DB
A community-led vulnerabilities database
NVIDIA Windows GPU Display Driver and GeForce Experience software contain a vulnerability (CVE-2020-5964) in the service host component, where the application resources integrity check may be missed. The vulnerability was disclosed on June 24, 2020, affecting all versions of NVIDIA Windows GPU Display Driver and GeForce Experience versions prior to 3.20.4 (NVIDIA Advisory, GeForce Advisory).
The vulnerability resides in the service host component where application resources integrity verification can be bypassed. It has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H for the GPU Display Driver, and a score of 6.5 with vector string AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H for GeForce Experience. The vulnerability is classified under CWE-345 (Insufficient Verification of Data Authenticity) (NVD Database).
If successfully exploited, this vulnerability could lead to code execution, denial of service, or information disclosure on affected systems (NVIDIA Advisory).
The vulnerability requires local access and high privileges with user interaction for successful exploitation in GeForce Experience, while the GPU Display Driver variant requires local access with low privileges and no user interaction (NVD Database).
NVIDIA has released security updates to address this vulnerability. For GPU Display Driver, users should update to version 451.48 for R450 branch, 443.18 for R440 branch, 426.78 for R418 branch, or 392.61 for R390 branch. GeForce Experience users should update to version 3.20.4. Updates can be obtained through the NVIDIA Driver Downloads page or GeForce Experience client (NVIDIA Advisory, GeForce Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."