CVE-2022-28181 is a critical out-of-bounds write vulnerability in the NVIDIA GPU Display Driver for both Windows and Linux. An unprivileged network user can trigger this flaw with a specially crafted shader, potentially leading to code execution, denial of service, privilege escalation, information disclosure, and data tampering. With a CVSS score of 9.9, this vulnerability is easily exploitable over the network with low complexity and no user interaction, allowing for complete compromise of confidentiality, integrity, and availability. While not currently in the CISA KEV catalog, there is some community discussion and media coverage, though no public exploit code or Metasploit modules are available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.8CPE matchmatch criteria | cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.3CPE matchmatch criteria | cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | ||
14.0CPE matchmatch criteria | cpe:2.3:a:nvidia:virtual_gpu:14.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.