CVE-2016-8810
HIGHNVIDIA GPU Driver R340 < 342.00 & R375 < 375.63 - DoS or Privilege Escalation via Unvalidated Array Index
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-8810. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit targets a buffer overflow in the DxgkDdiEscape handler (escape 0x100009a) due to improper bounds checking and potential integer overflow in size calculations. It demonstrates a crash in the NVIDIA driver (nvlddmkm) on Windows 10 x64, leading to a PAGE_FAULT_IN_NONPAGED_AREA.
Description
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100009a where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Exploits (1)
The exploit targets a buffer overflow in the DxgkDdiEscape handler (escape 0x100009a) due to improper bounds checking and potential integer overflow in size calculations. It demonstrates a crash in the NVIDIA driver (nvlddmkm) on Windows 10 x64, leading to a PAGE_FAULT_IN_NONPAGED_AREA.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H