CVE-2022-42266

MEDIUM

NVIDIA GPU Display Driver for Windows - Unauthorized Sensitive Information Exposure via DxgkDdiEscape Handler

Title source: llm
STIX 2.1

Description

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
nvidia/cloud_gaming < 527.27
nvidia/virtual_gpu < 11.11
Published Dec 30, 2022
Tracked Since Feb 18, 2026