CVE-2016-7386 is a kernel memory leakage vulnerability affecting NVIDIA Quadro, NVS, and GeForce GPU Display Drivers for Windows, specifically versions R340 before 342.00 and R375 before 375.63. The flaw in the nvlddmkm.sys handler for DxgDdiEscape ID 0x70000D4 allows an attacker to leak kernel memory contents to user space via an uninitialized buffer. With a CVSS v3 score of 5.5 (Medium), this vulnerability has a low attack complexity and requires local user privileges, potentially leading to high confidentiality impact but no integrity or availability impact. While not actively exploited in the wild (KEV: No), a public exploit (EDB-40656) exists, though there is no evidence of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.