CVE-2016-8811 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.61% — more likely to be exploited than 75% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-11-08 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows |
| nvidia | gpu driver |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NVIDIA Driver - No Bounds Checking in Escape 0x7000170 | 2016-10-31 |
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/4247
- http://www.securityfocus.com/bid/93988
- https://support.lenovo.com/us/en/solutions/LEN-10822
- https://www.exploit-db.com/exploits/40662/
- http://nvidia.custhelp.com/app/answers/detail/a_id/4247
- http://www.securityfocus.com/bid/93988
- https://support.lenovo.com/us/en/solutions/LEN-10822
- https://www.exploit-db.com/exploits/40662/
→ the Explorer · watch your stack · NVD