NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default permissions for an object exposes it to an unintended actor
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/4841 | vendor advisory |
https://support.lenovo.com/us/en/product_security/LEN-28096 | third party advisory |