Businesses urged to patch against 'highly severe' Nvidia flaws

GeForce, Quadro and Tesla GPUs are affected by bugs that could lead to local code execution

A host of Nvidia graphics chips are affected by five dangerous vulnerabilities ranging in severity, including one that could allow an attacker to execute malicious code locally.

Organisations using NVIDIA's GeForce, Quadro and Tesla graphics processing units (GPUs) have been urged to update their drivers immediately after the graphics giant published details around the recently-discovered flaws.

Advertisement - Article continues below

The most severe flaw, dubbed CVE-2019-5683 and rated 8.8 via CVSS V3 standards, involves a flaw in a component of the Windows GPU Display Driver software. If exploited, a malicious actor can install malware on a victim's machine.

More specifically, if an attacker has gained access to the user mode video driver trace logger component, they are able to create a hard link because the software does not check for such an attack.

Successfully taking advantage of this vulnerability could lead to local code execution, denial of service, as well as privilege escalation attacks.

Elsewhere, two separate flaws with DirectX drivers, each given a severity rating of 7.8, would also allow an attacker to execute malicious code or launch a denial of service attack.

Both flaws were first discovered by Cisco Talos security researcher Piotr Bania, who noted that VMware's ESXi, Workstation and Fusion products are affected by the out-of-bounds write vulnerability triggered through a specially crafted shader file.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Quadro graphics chips are conventionally used in workstations that are used to run profession computer-aided design (CAD) and similar heavy-duty graphics work, alongside machine learning applications and intensive calculations.

Tesla GPUs, meanwhile, are industrial units deployed on server platforms, given these chips' capacity to perform highly precise computations.

Businesses likely to deploy either variant of the Nvidia GPU, as well as GeForce GPUs fitted into notebook devices, are being urged to upgrade their drivers as soon as possible to the latest version.

These flaws are rated highly severe, but require an attacker to have close physical proximity to a targeted device, so are far less likely to be executed compared with remote-code execution vulnerabilities.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/privacy/355182/government-to-launch-coronavirus-contact-tracking-app
privacy

UK government to launch coronavirus 'contact tracking' app

1 Apr 2020
Visit/software/video-conferencing/355180/zoom-does-not-use-end-to-end-encrypted
video conferencing

Zoom admits meetings don't use end-to-end encryption

1 Apr 2020
Visit/security/malware/355093/evasive-malware-threats-are-surging
malware

Evasive malware threats doubled in 2019

24 Mar 2020
Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020

Most Popular

Visit/security/privacy/355155/zoom-kills-facebook-integration-after-data-transfer-backlash
privacy

Zoom kills Facebook integration after data transfer backlash

30 Mar 2020
Visit/security/data-breaches/355173/marriott-hit-by-data-breach-exposing-personal-data-of-52-million
data breaches

Marriott data breach exposes personal data of 5.2 million guests

31 Mar 2020
Visit/security/cyber-crime/355171/fbi-warns-of-zoom-bombing-hackers-amidst-coronavirus-usage-spike
cyber crime

FBI warns of ‘Zoom-bombing’ hackers amid coronavirus usage spike

31 Mar 2020
Visit/data-insights/data-management/355170/oracle-cloud-courses-are-free-during-coronavirus-lockdown
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020