CVE-2015-7866 describes an unquoted Windows search path vulnerability in the NVIDIA GPU graphics driver's Smart Maximize Helper (nvSmartMaxApp.exe), affecting specific driver versions on Windows. This local privilege escalation flaw allows an attacker to gain full control over the system by placing a malicious executable, such as "C:\Program.exe," in a predictable path. Rated with a CVSS score of 7.2, it presents a high severity risk due to its low attack complexity and complete impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 341.92CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 352, < 354.35CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 358, < 358.87CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.