CVE-2022-42291

HIGH

NVIDIA GeForce Experience < 3.27.0.112 - Data Tampering via Installer Windows Junction Handling

Title source: llm
STIX 2.1

Description

NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the exploitation of this vulnerability, which requires the user to explicitly launch the installer from the compromised directory.

References (1)

Core 1

Scores

CVSS v3 8.2
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1386 CWE-59
Status published
Products (1)
nvidia/geforce_experience < 3.27.0.112
Published Feb 07, 2023
Tracked Since Feb 18, 2026