CVE-2022-28192
CVE-2022-28192
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 May 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected products
NVIDIA · NVIDIA Virtual GPU Software and NVIDIA Cloud GamingWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →