EVGA

Urgent security warning: NVIDIA urges GeForce users to update drivers

Author
Cool GTX
EVGA Forum Moderator
  • Total Posts : 30997
  • Reward points : 0
  • Joined: 2010/12/12 14:22:25
  • Location: Folding for the Greater Good
  • Status: offline
  • Ribbons : 123
2024/11/08 03:46:26 (permalink)
Urgent security warning: NVIDIA urges GeForce users to update drivers – Eight critical vulnerabilities discovered5. November 2024 06:00
Samir Bashir
 
(Excerpt)
 

Details of the security vulnerabilities

The identified vulnerabilities affect both the NVIDIA GPU Display Driver and the NVIDIA VGPU software. These driver components control the display and management of graphical content on Windows and Linux systems. The vulnerabilities may allow an attacker with elevated privileges to execute malicious code or gain access to sensitive data. Possible attack scenarios include code execution, denial of service, escalation of privileges and information theft. The risk is rated between 7.1 and 8.2 on the CVSS scale, underlining the severity of the threat.

Affected driver versions and recommended updates

(formatting changed from article & bold added for clarity)


To minimize the risk, NVIDIA has provided updated driver versions that close the vulnerabilities. The recommended versions vary depending on the operating system and GPU model.


- Windows users using GeForce, RTX, Quadro or NVS GPUs should update to versions 566.03, 553.24 or 538.95.


- Versions 553.24 and 538.95 are intended for NVIDIA Tesla GPUs.


- Linux users should install versions 565.57.01, 550.127.05 or 535.216.01, depending on the GPU model, to ensure that the gaps are closed.
 

Learn your way around the EVGA Forums, Rules & limits on new accounts Ultimate Self-Starter Thread For New Members

I am a Volunteer Moderator - not an EVGA employee

Older RIG projects RTX Project  Nibbler


 When someone does not use reason to reach their conclusion in the first place; you can't use reason to convince them otherwise!
#1
yodap
CLASSIFIED Member
  • Total Posts : 4664
  • Reward points : 0
  • Joined: 2011/05/15 06:13:40
  • Location: NY, Upstate
  • Status: offline
  • Ribbons : 8
Re: Urgent security warning: NVIDIA urges GeForce users to update drivers 2024/11/08 04:52:59 (permalink)

 


 

 
#2
bill1024
Omnipotent Enthusiast
  • Total Posts : 11387
  • Reward points : 0
  • Joined: 2008/10/18 01:01:10
  • Status: offline
  • Ribbons : 65
Re: Urgent security warning: NVIDIA urges GeForce users to update drivers 2024/11/08 06:36:14 (permalink)
I don’t understand one thing here, if the attacker already has elevated privileges on your computer isn’t it a little bit too late to change the drivers?

 Life is too short to carry a cheap pocket knife

   
 
#3
bdary
Omnipotent Enthusiast
  • Total Posts : 10534
  • Reward points : 0
  • Joined: 2008/04/25 14:08:16
  • Location: Florida
  • Status: offline
  • Ribbons : 118
Re: Urgent security warning: NVIDIA urges GeForce users to update drivers 2024/11/08 07:29:59 (permalink)
Thanks for the heads-up.


 
 
 
 
 
 
 
 
 
 
 
#4
Cool GTX
EVGA Forum Moderator
  • Total Posts : 30997
  • Reward points : 0
  • Joined: 2010/12/12 14:22:25
  • Location: Folding for the Greater Good
  • Status: offline
  • Ribbons : 123
Re: Urgent security warning: NVIDIA urges GeForce users to update drivers 2024/11/08 09:25:25 (permalink)
bill1024
I don’t understand one thing here, if the attacker already has elevated privileges on your computer isn’t it a little bit too late to change the drivers?

 
 
I think the security flaws allow the elevated privileges
 
 
 
Below, is what was said on PCWord: (excerpt)
The scope of the security flawsAccording to Nvidia, it’s possible for attackers to gain access to your entire system by exploiting one of the vulnerabilities. With this kind of access, hackers can not only infiltrate and execute malicious code in your PC, but also read and steal personal data.
The vulnerabilities affect GeForce software, Nvidia RTX, Quadro, NVS, and Tesla, both under Windows and Linux.
Nvidia hasn’t explicitly said whether any of these vulnerabilities are already being exploited in the wild. However, as all GeForce graphics cards are affected, it’s probably a far-reaching problem.

Learn your way around the EVGA Forums, Rules & limits on new accounts Ultimate Self-Starter Thread For New Members

I am a Volunteer Moderator - not an EVGA employee

Older RIG projects RTX Project  Nibbler


 When someone does not use reason to reach their conclusion in the first place; you can't use reason to convince them otherwise!
#5
Landvader07
New Member
  • Total Posts : 15
  • Reward points : 0
  • Joined: 2024/08/05 14:12:15
  • Location: Huntersville, North Carolina
  • Status: offline
  • Ribbons : 0
Re: Urgent security warning: NVIDIA urges GeForce users to update drivers 2024/11/08 10:14:46 (permalink)
I still don't get how a driver could affect a attacker getting in to your PC. Wouldn't that be your anti-virus job to keep attackers out and your anti-virus or windows defenders fault?
#6
bill1024
Omnipotent Enthusiast
  • Total Posts : 11387
  • Reward points : 0
  • Joined: 2008/10/18 01:01:10
  • Status: offline
  • Ribbons : 65
Re: Urgent security warning: NVIDIA urges GeForce users to update drivers 2024/11/08 10:55:34 (permalink)
How it's written and how I am reading it:
The vulnerabilities may allow an attacker WITH elevated privileges to execute malicious code or gain access to sensitive data. Possible attack scenarios include code execution, denial of service.....
 
How I would write it if the driver gave them the privilege's.
 
The vulnerabilities may give an attacker elevated privileges to be able to execute malicious code yada yada yada....
 
I could be wrong, I was never an English teacher. Could be reading it wrong. Or maybe something did not come out right in translation. Either way I guess I'll update the drivers when I get a chance.
 
 
 

 Life is too short to carry a cheap pocket knife

   
 
#7
Jump to:
  • Back to Mobile