CVE-2016-3161

HIGH

NVIDIA GeForce Experience - Unquoted Service Path Privilege Escalation via GameStream Service

Title source: llm
STIX 2.1

Description

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-3161 ID is for the GameStream unquoted service path.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://nvidia.custhelp.com/app/answers/detail/a_id/4213
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93251

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
n/a/Quadro, NVS, GeForce (all versions) Quadro, NVS, GeForce (all versions)
nvidia/geforce_experience < -
Published Nov 08, 2016
Tracked Since Feb 18, 2026