NVIDIA GPU Display Driver - Windows user mode layer: The user mode driver layer lets an unprivileged user read
Impact
The user mode driver layer lets an unprivileged user read or modify files critical to the driver, which is a straightforward path to SYSTEM on the node. Only matters to you if you run Windows GPU nodes - VDI/DaaS session hosts, cloud-gaming fleets, Windows render or CAE farms.
Who can reach it
Local and unprivileged on a Windows GPU node, through the driver's private IOCTL / DxgkDdiEscape path. Any interactive or RDP/Citrix session with a GPU handle can call it, so on a multi-session VDI host every logged-in user is in range.
What to do
Install the fixed Windows display driver from bulletin 5415. Cost: a Windows display-driver replacement reboots the node, so drain sessions first. Linux-only fleets can skip this entirely.
References
Related entries
- NVIDIA GPU Display Driver (Windows user mode layer): out-of-bounds reads reachable by an unprivileged local userCVE-2024-0117 · NVIDIA GPU Display Driver - Windows user mode layerHigh
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2023-0184 · GPU Display DriverHigh
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2023-0189 · GPU Display DriverHigh
- DGX H100 BMC (openBMC): RCE on BMC (web server plugin stack overflow)CVE-2023-25528 · DGX H100 BMC (openBMC)High
- UFM Enterprise / UFM Appliance / UFM CyberAI: Fabric-manager privesc, data corruption, service disruption via improperCVE-2024-0130 · UFM Enterprise / UFM Appliance / UFM CyberAIHigh
- NVIDIA App: Local privescCVE-2025-23253 · NVIDIA AppHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.