CVE-2016-8808 is a vulnerability in the NVIDIA Windows GPU Display Driver (nvlddmkm.sys) affecting Quadro, NVS, and GeForce products, specifically versions R340 before 342.00 and R375 before 375.63. It stems from a missing bounds check when processing DxgDdiEscape ID 0x70000d5, allowing an unvalidated user-supplied value to be used as an array index. This flaw carries a CVSSv3 score of 7.8 (High), indicating a local attack vector with low complexity, and can lead to denial of service or potential escalation of privileges. While not listed in CISA's KEV catalog, public exploit code exists (EDB-40666), though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 340, < 342.00CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* | ||
>= 375, < 375.63CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.