CVE-2016-7387 is a high-severity vulnerability affecting NVIDIA Windows GPU Display Drivers (R340 before 342.00 and R375 before 375.63) for Quadro, NVS, and GeForce products. It stems from a lack of input validation in the kernel mode layer (nvlddmkm.sys) when handling DxgDdiEscape ID 0x600000D, allowing a user-provided value to be used as an array index. This flaw can lead to denial of service or potential escalation of privileges with low attack complexity and local access. While not actively exploited in the wild and not on the KEV catalog, public exploit code exists (EDB-40659), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.