CVE-2016-8812

high
Published 2016-11-08 ยท Modified 2026-05-06
CVSS v3
8.8
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.8

Description

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.

Predictions

Exploit likelihood
82%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-40660 local windows verified
Google Security Research ยท 2016-10-31

NVIDIA Driver - NvStreamKms 'PsSetCreateProcessNotifyRoutineEx Local Stack Buffer Overflow Callback / Local Privilege Escalation

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
nvidia nvidiageforce_experience{"endIncluding":"-"}
nvidia nvidiageforce_910m-
nvidia nvidiageforce_920m-
nvidia nvidiageforce_920mx-
nvidia nvidiageforce_930m-
nvidia nvidiageforce_930mx-
nvidia nvidiageforce_940m-
nvidia nvidiageforce_940mx-
nvidia nvidiageforce_945m-
nvidia nvidiageforce_gt_710-
nvidia nvidiageforce_gt_730-
nvidia nvidiageforce_gtx_1050-
nvidia nvidiageforce_gtx_1060-
nvidia nvidiageforce_gtx_1070-
nvidia nvidiageforce_gtx_1080-
nvidia nvidiageforce_gtx_950m-
nvidia nvidiageforce_gtx_960m-
nvidia nvidiageforce_gtx_965m-
nvidia nvidianvs_310-
nvidia nvidianvs_315-
nvidia nvidianvs_510-
nvidia nvidianvs_810-
nvidia nvidiaquadro_k1200-
nvidia nvidiaquadro_k420-
nvidia nvidiaquadro_k620-
nvidia nvidiaquadro_m1000m-
nvidia nvidiaquadro_m2000-
nvidia nvidiaquadro_m2000m-
nvidia nvidiaquadro_m3000m-
nvidia nvidiaquadro_m4000-
nvidia nvidiaquadro_m4000m-
nvidia nvidiaquadro_m5000-
nvidia nvidiaquadro_m5000m-
nvidia nvidiaquadro_m500m-
nvidia nvidiaquadro_m5500-
nvidia nvidiaquadro_m6000-
nvidia nvidiaquadro_m600m-
nvidia nvidiaquadro_p5000-
nvidia nvidiaquadro_p6000-
nvidia nvidiatitan_x-

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.