Usługa NVIDIA NvContainer dla Windows zawiera podatność w stosowaniu OpenSSL, gdzie atakujący może wykorzystać problem hard-coded'ej stałej poprzez skopiowanie złośliwej DLL w hard-coded'ą ścieżkę. Pomyślny exploit tej podatności może prowadzić do code execution, denial of service, escalation of privileges, information disclosure lub data tampering.
▸ Pokaż oryginał (EN)
NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEDoSContainer
CWE