CVE-2016-8827
medium
CVSS v3
6.5
CVSS v2
5.0
VIR risk
6.5
Description
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@nvidia.com — https://nvidia.custhelp.com/app/answers/detail/a_id/5033
Vendor advisory: psirt@nvidia.com — http://nvidia.custhelp.com/app/answers/detail/a_id/4279
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| nvidia | geforce_experience | {"startIncluding":"3.0","endExcluding":"3.1.0.52"} | 3.1.0.52 |
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/4279
- http://www.securityfocus.com/bid/94964
- https://nvidia.custhelp.com/app/answers/detail/a_id/5033
- https://nvidia.custhelp.com/app/answers/detail/a_id/5155
- http://nvidia.custhelp.com/app/answers/detail/a_id/4279
- http://www.securityfocus.com/bid/94964
- https://nvidia.custhelp.com/app/answers/detail/a_id/5033
- https://nvidia.custhelp.com/app/answers/detail/a_id/5155
CWEs
CWE-22
Verify integrity in audit chain (admin only). AS-IS.