NVIDIA GPU Display Driver - Windows DirectX 11 user mode driver (nvwgf2um.dll / nvwgf2umx.dll): A crafted shader causes
Impact
A crafted shader causes an out-of-bounds write in the DX11 user mode driver, reaching code execution with a changed scope. NVIDIA scores it AV:Network with no privileges required, which is the signature of a shader delivered over a remote rendering or browser path rather than by a local user. For a cloud-gaming, VDI or remote-workstation operator this is the bug in the 2022 set that actually crosses a customer boundary.
Who can reach it
Network, no privileges. The attacker supplies a shader that the victim's GPU compiles and runs - via a web page, a streamed application, or a shared render pipeline. On a multi-session Windows host this reaches other users' sessions.
What to do
Install the fixed Windows driver from bulletin 5353. Cost: node reboot after driver replacement, so drain sessions. Until patched, the only real compensating control is not accepting untrusted shader input, which is not an option for a cloud-gaming or remote-workstation product.
References
Related entries
- GPU Display Driver (kernel): Local privesc to host root (kernel buffer overflow)CVE-2022-34671 · GPU Display Driver (kernel)High
- Container Toolkit: Container escape / host file write via symlink followingCVE-2025-23267 · Container ToolkitHigh
- Container Toolkit: Container escape to host root via TOCTOU raceCVE-2026-24260 · Container ToolkitHigh
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A local user gets elevated enough to rewrite display configurationCVE-2021-1051 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
- DGX servers (BMC firmware < 2.09.00): RCE on BMC (buffer overflow)CVE-2022-42271 · DGX servers (BMC firmware < 2.09.00)High
- NVIDIA DCGM - nv-hostengine: A heap-based buffer overflow reachable through the bound socket gives denial of serviceCVE-2023-0208 · NVIDIA DCGM - nv-hostengineHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.