CVE-2016-8811 describes a vulnerability in the NVIDIA Windows GPU Display Driver (nvlddmkm.sys) affecting Quadro, NVS, and GeForce products, specifically versions R340 before 342.00 and R375 before 375.63. The flaw lies in the DxgDdiEscape ID 0x7000170 handler, which fails to validate the size of an input buffer. This oversight can lead to a denial of service or, more critically, potential escalation of privileges. With a CVSSv3 score of 7.8 (High), this vulnerability is locally exploitable with low attack complexity, potentially resulting in high impact to confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking Metasploit/Nuclei modules, public exploit code exists on ExploitDB (EDB-40662), though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.