CVE-2015-1170
NVIDIA Display Driver <309.08-347.52 - Privilege Escalation
Title source: llmDescription
The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client impersonation levels when performing a "kernel administrator check," which allows local users to gain administrator privileges via unspecified API calls.
References (6)
Core 6
Core References
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=143013598825091&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032013
Various Sources x_refsource_confirm
https://support.lenovo.com/product_security/nvidia_windows_privilege
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=142781493222653&w=2
Various Sources x_refsource_confirm
https://support.lenovo.com/us/en/product_security/nvidia_windows_privilege
Vendor Advisory x_refsource_confirm
http://nvidia.custhelp.com/app/answers/detail/a_id/3634
Scores
EPSS
0.0005
EPSS Percentile
15.0%
Details
CWE
CWE-264
Status
published
Products (4)
nvidia/gpu_driver_r304
< 309.07
nvidia/gpu_driver_r340
< 341.43
nvidia/gpu_driver_r343
< 345.19
nvidia/gpu_driver_r346
< 347.51
Published
Mar 06, 2015
Tracked Since
Feb 18, 2026