ID

VAR-201304-0128


CVE

CVE-2013-0109


TITLE

NVIDIA Windows video card drivers contain multiple vulnerabilities

Trust: 0.8

sources: CERT/CC: VU#957036

DESCRIPTION

The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application. NVIDIA video card drivers contain multiple vulnerabilities. NVIDIA Graphics Driver for Windows is prone to a local privilege-escalation vulnerability. A local attacker may exploit this issue to gain escalated privileges and execute arbitrary code with administrator privileges. Successful exploits will result in the complete compromise of affected computers. NVIDIA Graphics Driver for Windows versions prior to 307.83 and 311.00 are vulnerable

Trust: 2.61

sources: NVD: CVE-2013-0109 // CERT/CC: VU#957036 // JVNDB: JVNDB-2013-002164 // BID: 58459

AFFECTED PRODUCTS

vendor:nvidiamodel:display driverscope:eqversion:310.00

Trust: 1.6

vendor:nvidiamodel:display driverscope:lteversion:307.00

Trust: 1.0

vendor:nvidiamodel: - scope: - version: -

Trust: 0.8

vendor:nvidiamodel:display driverscope:eqversion:of nvidia driver 311.00

Trust: 0.8

vendor:nvidiamodel:display driverscope:ltversion:310

Trust: 0.8

vendor:nvidiamodel:display driverscope:eqversion:307.00

Trust: 0.6

sources: CERT/CC: VU#957036 // JVNDB: JVNDB-2013-002164 // CNNVD: CNNVD-201303-280 // NVD: CVE-2013-0109

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-0109
value: HIGH

Trust: 1.0

NVD: CVE-2013-0109
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201303-280
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2013-0109
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2013-002164 // CNNVD: CNNVD-201303-280 // NVD: CVE-2013-0109

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2013-002164 // NVD: CVE-2013-0109

THREAT TYPE

local

Trust: 0.9

sources: BID: 58459 // CNNVD: CNNVD-201303-280

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201303-280

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-002164

PATCH

title:NVIDIA Product Securityurl:http://www.nvidia.com/object/product-security.html

Trust: 0.8

title:NVIDIA Driver Downloadsurl:http://www.nvidia.com/Download/index.aspx

Trust: 0.8

title:NVIDIA Software Fix for Windows Display Driver Security Vulnerabilitiesurl:https://nvidia.custhelp.com/app/answers/detail/a_id/3288

Trust: 0.8

title:NVIDIA社ディスプレイドライバーの脆弱性に関するお知らせurl:http://www.fmworld.net/biz/common/nvidia/

Trust: 0.8

title:NVGuardServiceurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=45700

Trust: 0.6

sources: JVNDB: JVNDB-2013-002164 // CNNVD: CNNVD-201303-280

EXTERNAL IDS

db:CERT/CCid:VU#957036

Trust: 3.2

db:NVDid:CVE-2013-0109

Trust: 2.7

db:JVNid:JVNVU93435452

Trust: 0.8

db:JVNDBid:JVNDB-2013-002164

Trust: 0.8

db:SECUNIAid:52546

Trust: 0.6

db:CNNVDid:CNNVD-201303-280

Trust: 0.6

db:BIDid:58459

Trust: 0.3

sources: CERT/CC: VU#957036 // BID: 58459 // JVNDB: JVNDB-2013-002164 // CNNVD: CNNVD-201303-280 // NVD: CVE-2013-0109

REFERENCES

url:http://www.kb.cert.org/vuls/id/957036

Trust: 2.4

url:http://www.nvidia.com/object/product-security.html

Trust: 1.6

url:http://nvidia.custhelp.com/app/answers/detail/a_id/3288

Trust: 0.8

url:http://www.nvidia.com/download/index.aspx?lang=en-us

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-0109

Trust: 0.8

url:http://jvn.jp/cert/jvnvu93435452/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-0109

Trust: 0.8

url:http://secunia.com/advisories/52546

Trust: 0.6

url:http://www.nvidia.com

Trust: 0.3

sources: CERT/CC: VU#957036 // BID: 58459 // JVNDB: JVNDB-2013-002164 // CNNVD: CNNVD-201303-280 // NVD: CVE-2013-0109

CREDITS

Reported by the vendor.

Trust: 0.3

sources: BID: 58459

SOURCES

db:CERT/CCid:VU#957036
db:BIDid:58459
db:JVNDBid:JVNDB-2013-002164
db:CNNVDid:CNNVD-201303-280
db:NVDid:CVE-2013-0109

LAST UPDATE DATE

2025-04-11T23:01:51.142000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#957036date:2014-07-30T00:00:00
db:BIDid:58459date:2013-12-17T12:59:00
db:JVNDBid:JVNDB-2013-002164date:2013-04-10T00:00:00
db:CNNVDid:CNNVD-201303-280date:2013-03-15T00:00:00
db:NVDid:CVE-2013-0109date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#957036date:2013-03-21T00:00:00
db:BIDid:58459date:2013-02-15T00:00:00
db:JVNDBid:JVNDB-2013-002164date:2013-04-10T00:00:00
db:CNNVDid:CNNVD-201303-280date:2013-03-15T00:00:00
db:NVDid:CVE-2013-0109date:2013-04-08T16:55:01.977