CVE-2016-7385 is a vulnerability in the NVIDIA Windows GPU Display Driver (nvlddmkm.sys) affecting Quadro, NVS, and GeForce products, specifically versions R340 before 342.00 and R375 before 375.63. It involves a lack of input validation for a user-provided value used as an array index, leading to a high-severity risk of denial of service or potential escalation of privileges. The attack vector is local with low complexity, and the CVSS v3 score is 7.8 (HIGH). While not actively exploited in the wild and not on the KEV catalog, public exploit code exists (EDB-40657), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.