CVE-2021-23175 Information

Description

NVIDIA GeForce Experience contains a vulnerability in user authorization where GameStream does not correctly apply individual user access controls for users on the same device which with user intervention may lead to escalation of privileges information disclosure data tampering and denial of service affecting other resources beyond the intended security authority of GameStream.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Reference

https://nvidia.custhelp.com/app/answers/detail/a_id/5295

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.2

Share on: