CVE-2019-5701 is a binary planting vulnerability affecting NVIDIA GeForce Experience versions prior to 3.20.0.118 when GameStream is enabled. An attacker with local system access can exploit this by loading unvalidated Intel graphics driver DLLs, potentially leading to denial of service, information disclosure, or privilege escalation through code execution. Rated 7.8 HIGH, this vulnerability has a low attack complexity and requires user interaction, but can result in high impact across confidentiality, integrity, and availability. While no public exploit code exists (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, though it is not currently on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.20.0.118CPE matchmatch criteria | cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.