CVE-2019-5676 is a high-severity vulnerability affecting NVIDIA Windows GPU Display driver software and GeForce Experience, allowing for escalation of privileges through a binary planting or DLL preloading attack. An attacker with high privileges can exploit this by incorrectly loading Windows system DLLs without proper validation, leading to arbitrary code execution. Despite a CVSS score of 6.7 (MEDIUM), the potential impact is high across confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 410, < 412.36CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* | ||
>= 418, < 425.51CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* | ||
>= 430, < 430.64CPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:* | ||
< 3.19CPE matchmatch criteria | cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.