NVIDIA has released security updates to address security vulnerabilities identified in its GPU Display and CUDA drivers and Virtual GPU Manager software that could lead to code execution, DoS, privilege escalation, and information disclosure on Windows and Linux computers.

All of the flaws being patched today require local user and cannot be exploited remotely, with attackers first having to break into the exposed machines locally to launch attacks designed to exploit these bugs.
Once this is achieved, they could exploit them by remotely "planting" malicious code or tools that target one of these issues on devices running vulnerable NVIDIA drivers.
High severity issues affecting Windows, Linux devices
By exploiting these vulnerabilities, attackers can escalate privileges to gain rights above those initially granted by the operating system, to render unpatched systems/machines temporarily unusable, trigger DoS situations, or execute malicious code locally on compromised Windows and Linux.
The bugs come with CVSS V3 baseline scores ranging from 4.4 to 7.8, with six of them rated as high risk.
The software security flaws that NVIDIA addresses as part of the June 2020 security update are listed below along with the base CVSS V3 scores they have received.
NVIDIA GPU Display Driver
- CVE‑2020‑5962 (score 7.8)
- CVE‑2020‑5963 (score 7.8)
- CVE‑2020‑5964 (score 6.5)
- CVE‑2020‑5965 (score 5.5)
- CVE‑2020‑5966 (score 5.5)
- CVE‑2020‑5967 (score 5.5)
NVIDIA vGPU Software
- CVE‑2020‑5968 (score 7.8)
- CVE‑2020‑5969 (score 7.8)
- CVE‑2020‑5970 (score 7.8)
- CVE‑2020‑5971 (score 7.8)
- CVE‑2020‑5972 (score 5.5)
- CVE‑2020‑5973 (score 4.4)
According to NVIDIA's security advisory, the "risk assessment is based on the average risk across a diverse set of installed systems and may not represent the actual risk of your local installation."
The company also recommends consulting with an IT or security professional to accurately assess the risk of your specific system configuration.
Affected NVIDIA driver versions
The security includes the full list of software products and versions affected by the bugs fixed by NVIDIA today.
NVIDIA encourages customers to update their GeForce, Quadro, NVS, and Tesla Windows GPU display drivers, as well as the Virtual GPU Manager software, by applying the security updates available on the NVIDIA Driver Downloads page.
NVIDIA says that some customers who do not manually patch the flaws may also receive versions 451.55, 446.06, and 443.18 of the Windows GPU display drivers from computer , with the security updates released today bundled together.
Enterprise NVIDIA vGPU software users must log in to the NVIDIA Enterprise Application Hub to receive updates through the NVIDIA Licensing Center.
To find out which NVIDIA driver version you have installed on your computer, you can follow the procedure described here.
