HomeSecurityNVIDIA: Security update released for GeForce Experience

NVIDIA: Security update released for GeForce Experience

NVIDIA has released a security update for the NVIDIA GeForce Experience (GFE) Windows application to address vulnerabilities that could allow attackers to execute arbitrary code, escalate privileges, gain access to sensitive information, or cause a denial of service (DoS) on systems running unpatched software.

NVIDIA GFE is a utility for GeForce GTX graphics cards that “updates your drivers, automatically optimizes your game settings, and gives you the easiest way to share your best gaming moments with friends,” NVIDIA says.

NVIDIA

While these flaws require attackers to have local user access and cannot be exploited remotely, they can be exploited with malicious tools deployed on systems running vulnerable versions of NVIDIA GFE.

Furthermore, attacks that would exploit these bugs have low complexity according to NVIDIA, while also requiring low privileges and no user interaction.

CVE‑2020‑5977, the highest severity bug patched by NVIDIA today, can lead to privilege escalation and code execution after a successful exploit.

It also allows attackers to render Windows computers running unpatched NVIDIA GFE unusable by triggering a denial of service condition.

The vulnerability CVE‑2020‑5977 was reported by Xavier DANEST of Decathlon and consists of an uncontrolled search path used when loading an NVIDIA Web Helper NodeJS Web Server node module.

The other high-severity bug, CVE‑2020‑5990, exists in the ShadowPlay component and was reported by Hashim Jawad of ACTIVELabs.

You can see below the three vulnerabilities fixed in the October 2020 security update along with the base CVSS V3 score assigned by NVIDIA.

NVIDIA: Security update released for GeForce Experience

NVIDIA says that the “risk assessment is based on an average risk across a diverse set of installed systems and may not represent the actual risk of your local installation.”

The company also advises “consulting with a security or IT professional to assess the risk for your specific configuration.”

Affected GeForce Experience versions

The vulnerabilities only affect computers running versions of Windows and NVIDIA GeForce Experience prior to 3.20.5.70, the version that comes with fixes for the three bugs.

To apply the security update, you must download the latest software version (i.e. 3.20.5.70) from the “GeForce Experience Downloads” page or launch the GFE client to apply it automatically via the built-in update mechanism.

In July, NVIDIA patched another security flaw in all GeForce Experience versions prior to 3.20.4 that could lead to code execution, denial of service, or privilege escalation.

Last month, the company also addressed several high-severity security issues in its Windows GPU display driver and Virtual GPU Manager.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS