peter bassill · operator
$ cve CVE-2015-7865 JSON

CVE-2015-7865 EXPLOIT

7.7
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users to gain privileges via a commandline in a number 2 command, which is stored in the HKEY_LOCAL_MACHINE explorer Run registry key, a different vulnerability than CVE-2011-4784.

Scoring

CVSS7.7 (HIGH, v2.0)
VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
EPSS2.63% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploityes
Published2015-11-24
Last modified2026-06-17

Affected (2)

VendorProduct
microsoftwindows
nvidiagpu driver

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD