CVE Vulnerabilities

CVE-2024-0085

Incorrect Privilege Assignment

Published: Jun 13, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Virtual_gpuNvidia*13.11 (excluding)
Virtual_gpuNvidia14.0 (including)16.6 (excluding)
Virtual_gpuNvidia17.0 (including)17.2 (excluding)

Potential Mitigations

References