CVE-2016-5852

HIGH

NVIDIA GeForce Experience - Unquoted Service Path Privilege Escalation via GameStream and NVTray Plugin

Title source: llm
STIX 2.1

Description

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-5852 ID is for the NVTray Plugin unquoted service path.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://nvidia.custhelp.com/app/answers/detail/a_id/4213
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93251

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
n/a/Quadro, NVS, GeForce (all versions) Quadro, NVS, GeForce (all versions)
nvidia/geforce_experience < -
Published Nov 08, 2016
Tracked Since Feb 18, 2026