All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a handle to a kernel object may be returned to the user, leading to possible denial of service or escalation of privileges.
The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95058 | vdb entry |
http://nvidia.custhelp.com/app/answers/detail/a_id/4257 | patch vendor advisory |