CVE-2016-1861
HIGHmacOS < 10.11.5 - Remote Code Execution in NVIDIA Graphics Drivers
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-1861. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit targets a kernel stack buffer overflow in the NVIDIA GeForce GPU driver (nvAPIClient::Escape) on macOS. It leverages insufficient bounds checking in the ::SetClocksShmoo method to overflow a stack buffer, potentially leading to privilege escalation.
Description
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.
Exploits (1)
This exploit targets a kernel stack buffer overflow in the NVIDIA GeForce GPU driver (nvAPIClient::Escape) on macOS. It leverages insufficient bounds checking in the ::SetClocksShmoo method to overflow a stack buffer, potentially leading to privilege escalation.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H