U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-1074

Change History

CVE Modified by NVIDIA Corporation 6/01/2021 3:15:07 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
NVIDIA Corporation AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Removed CVSS V3.1
NVIDIA Corporation AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

								
						
Removed CVSS V3.1 Reason
AC-No Race Condition

								
						
Removed CVSS V3.1 Reason
S-Unclear if Scope change occurs

								
						
Changed Description
NVIDIA Windows GPU Display Driver for Windows, R390 driver branch, contains a vulnerability in its installer where an attacker with local system access may replace an application resource with malicious files. Such an attack may lead to code execution, escalation of privileges, denial of service, or information disclosure.
NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.