[SOLVED] NVIDIA Issues Warning to Upgrade Drivers Due to Security Patches. !

Page 3 - Seeking answers? Join the Tom's Hardware community: where nearly two million members share solutions and discuss the latest tech.
Status
Not open for further replies.
D

Deleted member 2731765

Guest
Hello,

Just some heads-up. If you are currently using an NVIDIA GPU, then update your drivers asap. Nvidia has issued a new security bulletin which warns their users that their Geforce, Quadro and Tesla graphics cards could be leaving their systems vulnerable to five recently discovered security exploits.

NVIDIA has found a total of five security vulnerabilities with its Windows drivers for GeForce, Quadro and Tesla lineup of graphics cards. These new security risks are labeled as very dangerous and have the potential to cause local code execution, denial of service, or escalation of privileges, unless the system is updated. Users are advised to update their Windows drivers as soon as possible in order to stay secure and avoid all of these vulnerabilities.

Exploits are only accessible on Windows based OSes, starting from Windows 7 to Windows 10. However, one fact that's reassuring is that in order to exploit a system, attacker must have local access to the machine that is running NVIDIA GPU, as remote exploit can not happen.

https://nvidia.custhelp.com/app/answers/detail/a_id/4841/kw/Security Bulletin

The vulnerabilities are rated using CVSS V3 base scoring system and they are arranged as following:
  • CVE-2019-5683 - Most dangerous of all the vulnerabilities. This exploits uses driver's trace logger weakness to create hard links, that software does not check. Attacker could create any link without getting warned by the system and force local code execution, denial of service or escalation of privileges. It is rated with a score of 8.8.

  • CVE-2019-5684 - Vulnerability which uses carefully crafted shaders in order to cause out of bounds access to input texture array, possibly leading to denial of service or code execution. It is rated with a score of 7.8

  • CVE-2019-5685 - Vulnerability which also uses carefully crafted shaders in order to cause out of bounds access to shader local temporary array, possibly leading to denial of service or code execution as well. It is rated with a score of 7.8

  • CVE-2019-5686 - Vulnerability hidden in kernel mode layer handler for DxgkDdiEscape, which uses different data structures and DirectX API functions that are not always valid, leading to denial of service if the API function or data structure is incorrect. It is rated with a score of 5.6.

  • CVE-2019-5687 - Least dangerous exploit of all five. It is also a problem in kernel model layer handler for DxgkDdiEscape, which may put system at risk if incorrect default permissions are used for an object. This can lead to information disclosure or denial of service. It is rated with a score of 5.2.
 
  • Like
Reactions: Roland Of Gilead
Solution
Well to sum up the matter of using GEFORCE for drivers--

  1. I had no choice. Even when I had NO drivers (after DDU uninstall) I had to use GEFORCE. It's not just that you can't "install standard drivers over DCH " it's that you can't install them period.
  2. If as suggested here it is related to Win 10 pro, it might also be related to Win 10 Enterprise etc. That means there are a lot of people who have no choice but to use GEFORCE.
  3. If pre-mades also require it, that means even more people use GEFORCE.
  4. So there is little point in suggesting that downloading standard drivers from the web site is the best way to go as it is impossible for a large number of users and leads to the distracting concern that when the warning comes...
I'm stumped after looking through that.
I updated to 431.60 back on Aug 5 - also did manual search, but I was pointed to the standard driver package.

And at any rate notwithstanding the critical views expressed here Nvidia control panel gives Nvidia driver number same as post #45 that is 431.60 . So I would say that the manual download procedure recommended is on its way out and that those of us who received our Nvidia gpus as of -- well, yesterday -- are going to be doing it differently.

View: https://imgur.com/SKxeeOh
If I had to guess, the reason you're having to download DCH drivers is because of Windows Pro version.
You're not running a prebuilt, so the only thing that came to mind with preinstalled OEM packages were some of the extra features Pro has over Home.
 
  • Like
Reactions: gn842a
Well to sum up the matter of using GEFORCE for drivers--

  1. I had no choice. Even when I had NO drivers (after DDU uninstall) I had to use GEFORCE. It's not just that you can't "install standard drivers over DCH " it's that you can't install them period.
  2. If as suggested here it is related to Win 10 pro, it might also be related to Win 10 Enterprise etc. That means there are a lot of people who have no choice but to use GEFORCE.
  3. If pre-mades also require it, that means even more people use GEFORCE.
  4. So there is little point in suggesting that downloading standard drivers from the web site is the best way to go as it is impossible for a large number of users and leads to the distracting concern that when the warning comes up that you have to install the software something is going wrong, when in fact it is going the only way it can go given what OEMs are up to.
  5. The driver update obtained through GEFORCE 431.60 is the same as what people are getting without GEFORCE
  6. And from what I saw about the dates on the drivers 431.60 was available a week earlier through GEFORCE (7-16-19) than it was through standard download (7-23-19). This could be a good thing if the drivers are good and a bad thing if the drivers are glitchy, because being first isn't always good.
 
Last edited:
Solution
Status
Not open for further replies.