Release date:
Updated on:
Affected Systems:
NVIDIA Nvidia Display Driver
Description:
--------------------------------------------------------------------------------
Nvidia is a leading global manufacturer of graphics technology and digital media processors.
A privilege escalation vulnerability exists in the Windows Nvidia display driver service, allowing attackers to access the target machine to create super users with remote Root access permissions, completely bypassing DEP and ASLR protection.
The stack overflow vulnerability is caused by the failure to check the copy data of the memmove operation. The exploitation of a bypass DEP + ASLR +/GS + CoE is published in pastebin.com and has been deleted.
<* Source: Peter Winter-Smith (peter4020@hotmail.com)
Link: http://www.solidot.org/story? Sid = 1, 32884
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
NVIDIA
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.nvidia.com/