NVIDIA Virtual GPU Manager
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*
- <= 19.3
- <= 18.5
- <= 16.12
A use-after-free vulnerability has been identified in NVIDIA vGPU software, specifically within the Virtual GPU Manager component. This vulnerability allows a malicious guest to access heap memory after it has been freed, potentially leading to unauthorized code execution, privilege escalation, data tampering, denial of service, or information disclosure. The issue affects several different versions and branches of the vGPU software.
Exploitation of this vulnerability could result in unauthorized code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
Users can download the updated version of the vGPU software through the NVIDIA Licensing Portal. Instructions for updating can be found on the NVIDIA Product Security page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.