NVIDIA released security updates for multiple high-severity flaws in its GPU Display Driver for Windows and Linux, as well as in NVIDIA vGPU and Cloud Gaming software. The vulnerabilities include CVE-2024-0126, an improper input validation issue rated CVSS 8.2 that could let a local authenticated attacker escalate privileges and execute code, along with CVE-2024-0117 through CVE-2024-0121, which affect Windows user-mode components and can lead to out-of-bounds reads, information disclosure, denial of service, and in some cases further compromise with user interaction.
NVIDIA also patched virtualization-related flaws including CVE-2024-0127 and CVE-2024-0128, which affect supported hypervisors and Azure Stack HCI deployments and could enable improper resource access, data tampering, denial of service, privilege escalation, or code execution. Updated fixed versions were issued across major driver branches including R565, R550, and R535, with corresponding updates for GeForce, RTX, Quadro, NVS, Tesla, vGPU, and Cloud Gaming products, and defenders were urged to upgrade affected systems promptly.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
NVIDIA updated the security bulletin after its initial release, as reflected in the revision history. The edit was recorded separately from the original publication.
NVIDIA issued a security bulletin covering multiple high-severity vulnerabilities in GPU Display Driver software for Windows and Linux and in NVIDIA vGPU software. The bulletin documented issues including CVE-2024-0117 through CVE-2024-0121, CVE-2024-0126, CVE-2024-0127, and CVE-2024-0128, and provided updated driver and vGPU releases to remediate them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.