CVE-2016-8812
HIGHNVIDIA GeForce Experience <GFE 2.11.4.125-3.1.0.52 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-8812. PoCs published by Google Security Research.
AI-analyzed exploit summary The analysis details a buffer overflow vulnerability in NvStreamKms.sys due to incorrect use of wcscpy_s with a stack buffer, exploitable via UNC paths with forward slashes. The writeup includes technical details, crash context, and reproduction steps requiring a WebDAV server.
Description
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.
Exploits (1)
The analysis details a buffer overflow vulnerability in NvStreamKms.sys due to incorrect use of wcscpy_s with a stack buffer, exploitable via UNC paths with forward slashes. The writeup includes technical details, crash context, and reproduction steps requiring a WebDAV server.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H