Monday, March 10, 2025
HomeCVE/vulnerabilityNVIDIA Patch Multiple GPU Display Driver for Windows & Linux

NVIDIA Patch Multiple GPU Display Driver for Windows & Linux

Published on

SIEM as a Service

Follow Us on Google News

NVIDIA has issued essential security updates for its GPU Display Driver, addressing multiple vulnerabilities affecting Windows and Linux systems.

Users are urged to download and install these updates promptly via the NVIDIA Driver Downloads page or the NVIDIA Licensing Portal for vGPU software and Cloud Gaming updates. 

The vulnerabilities identified by their CVE IDs pose significant security risks, including potential code execution, denial of service, privilege escalation, information disclosure, and data tampering.

National Cybersecurity Awareness Month Cyber Challenges – Test your Skills Now

NVIDIA GPU Display Driver Vulnerabilities:

Below is a detailed table of the vulnerabilities addressed:

CVE IDDescriptionBase ScoreSeverityImpacts
CVE‑2024‑0126Another out-of-bounds read vulnerability in the Windows user mode layer.8.2HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0117Out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0118Similar out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0119Another out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0120Out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0121Out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering

NVIDIA vGPU Software Vulnerabilities:

CVE IDDescriptionBase ScoreSeverityImpacts
CVE‑2024‑0127Improper input validation in vGPU Manager for all hypervisors.7.8HighCode execution, privilege escalation, data tampering, denial of service, info disclosure
CVE‑2024‑0128Access to global resources in Virtual GPU Manager by guest OS users.7.1HighPrivilege escalation, information disclosure, and data tampering

These updates are crucial for maintaining system security and protecting sensitive information from potential threats.

NVIDIA recommends all users apply these patches immediately to mitigate risks associated with these vulnerabilities.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

WinDbg Vulnerability Allows Attackers to Execute Remote Code

Microsoft recently disclosed a critical vulnerability impacting its debugging tool, WinDbg, and associated .NET...

Thinkware Dashcam Vulnerability Leaks Credentials to Attackers

A series of significant security vulnerabilities have been discovered in the Thinkware Dashcam, specifically...

New Apache Traffic Server Flaws Allow Malformed Request Exploits

The Apache Software Foundation has disclosed several vulnerabilities affecting its Traffic Server software.These vulnerabilities...

Commvault Webserver Flaw Allows Attackers to Gain Full Control

Commvault has revealed a major vulnerability in its software that could allow malicious actors...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

WinDbg Vulnerability Allows Attackers to Execute Remote Code

Microsoft recently disclosed a critical vulnerability impacting its debugging tool, WinDbg, and associated .NET...

Thinkware Dashcam Vulnerability Leaks Credentials to Attackers

A series of significant security vulnerabilities have been discovered in the Thinkware Dashcam, specifically...

New Apache Traffic Server Flaws Allow Malformed Request Exploits

The Apache Software Foundation has disclosed several vulnerabilities affecting its Traffic Server software.These vulnerabilities...