CVE-2016-8809 is a vulnerability in the NVIDIA Windows GPU Display Driver (nvlddmkm.sys) affecting Quadro, NVS, and GeForce products, specifically versions R340 before 342.00 and R375 before 375.63. The flaw lies in the DxgDdiEscape ID 0x70001b2 handler, where an input buffer's size is not properly validated. This vulnerability carries a CVSSv3 score of 7.8 (High), indicating that a local attacker with low privileges can exploit it to cause a denial of service or potentially escalate privileges. While not actively exploited in the wild and not listed in CISA's KEV catalog, a public exploit (EDB-40664) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.