CVE-2015-7865
23Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 2.6%
de la publicación al arma0 días
Publicada en NVD24 nov
1ª PoC23 nov
probabilidad de explotación
2.6%top 16% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users to gain privileges via a commandline in a number 2 command, which is stored in the HKEY_LOCAL_MACHINE explorer Run registry key, a different vulnerability than CVE-2011-4784.
Productos afectados
n/a · n/aPoCs públicas encontradas — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38792cve_referencepacketstormsecurity.com/files/134520/NVIDIA-Stereoscopic-3D-Driver-Service-Arbitrary-Run-Key-Creation.htmlno verificadocve_referencewww.exploit-db.com/exploits/38792/no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://nvidia.custhelp.com/app/answers/detail/a_id/3807/kw/securityhttp://packetstormsecurity.com/files/134520/NVIDIA-Stereoscopic-3D-Driver-Service-Arbitrary-Run-Key-Creation.htmlhttps://code.google.com/p/google-security-research/issues/detail?id=515https://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04971867https://www.exploit-db.com/exploits/38792/http://www.securitytracker.com/id/1034173