NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A kernel object created by the escape handler gets default
CVE-2019-5687NVIDIA / GPU stackcurated
Impact
A kernel object created by the escape handler gets default permissions that expose it to accounts that should not reach it. Local privilege boundary erosion inside the driver.
Who can reach it
Any local user on the host who can open the over-permissive object.
What to do
Install the fixed Windows GPU Display Driver branch listed in the NVIDIA bulletin. nvlddmkm.sys is a kernel driver: the swap needs a host reboot, so on a Windows GPU node this is a drain-and-reboot, not a live driver reload. No VBIOS or BMC flash involved.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.