CVE-2016-8805 is a high-severity vulnerability affecting NVIDIA Quadro, NVS, and GeForce GPU display drivers for Windows (R340 before 342.00 and R375 before 375.63). It stems from a lack of input validation in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000014, allowing an unvalidated user-supplied value to be used as an array index. This flaw carries a CVSSv3 score of 7.8 (High) due to its potential for local privilege escalation or denial of service, requiring low attack complexity and no user interaction. While not listed on the KEV catalog, a public exploit (EDB-40667) exists, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.