CVE-2021-23175

NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:51

Type Values Removed Values Added
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5295 - Vendor Advisory () https://nvidia.custhelp.com/app/answers/detail/a_id/5295 - Vendor Advisory

Information

Published : 2021-12-23 16:15

Updated : 2024-11-21 05:51


NVD link : CVE-2021-23175

Mitre link : CVE-2021-23175

CVE.ORG link : CVE-2021-23175


JSON object : View

Products Affected

nvidia

  • geforce_experience

microsoft

  • windows
CWE
CWE-863

Incorrect Authorization