Skip to main content

An Nvidia vulnerability has been found. It’s time to update your drivers

Nvidia RTX 2060 Super and RTX 2070 Super review
Dan Baker/Digital Trends

Just this month, Nvidia posted a security bulletin on its site alerting consumers that GPUs in its GeForce, Quadro, and Tesla product lines were all affected by serious vulnerabilities. The vulnerabilities range in severity, but get as dangerous as local code execution and privilege escalation, and can be found in all versions of numerous driver tracks that the company provides for its hardware.

Notably, this includes the R430 line that powers the GeForce GPUs. While Nvidia has since issued new patched versions of all of its GeForce and many of its Quadro drivers, patches for some of its Quadro and Tesla drivers have not been released, and in some cases won’t be ready for two weeks.

Recommended Videos

The revelation of these substantial security flaws comes at an exceptionally awkward time for the GPU manufacturer, as it has just released its GeForce RTX Super line of graphics cards to capitalize on the post-E3 gaming excitement. Considering that concern for local privilege escalation vulnerabilities is often taken less seriously than more menacing remote code execution vulnerabilities due to the comparatively limited attack vector, gamers may not think to download and install a patch to their freshly purchased RTX Super GPU.

Please enable Javascript to view this content

These security holes also coincide with a recent disappointing showing against AMD. After AMD successfully tricked Nvidia into sabotaging its own RTX Super release with a less-than-competitive price point, marketing gleaming new GPUs with high-severity vulnerabilities right out of the gate surely feels like getting salt in its wound.

One saving grace for Nvidia is that some hardware manufacturers may bundle the driver update as part of larger system updates, but users should definitely not count on this.

As things currently stand, a local code execution bug combined with a privilege execution bug can leave unpatched devices open to physical attacks in which a malicious actor gains physical access to a device to give themselves administrator privileges and run arbitrary code. This kind of attack is not out of the question, as many of the devices containing vulnerable Nvidia graphics cards are used by creatives who may or may not have robust security models, or may be using publicly accessible devices like those in libraries or gaming lounges. Regardless, any consumer with affected hardware should download and run the patch installers Nvidia has provided (or will soon provide, for those that are not yet available) as soon as possible.

Jonathan Terrasi
Former Digital Trends Contributor
Jonathan has studiously followed trends in technology, particularly in information security and digital privacy, since 2014…
AMD might crush Nvidia with its laptop GPUs — but it’s silent on the desktop front
A woman sits by a desk and plays a game on a laptop equipped with an AMD processor.

AMD's graphics card lineup for laptops is on the way, and by the sound of it, it's shaping up to be pretty exciting -- and it's already bigger than Team Red's current desktop range.

According to a recent leak, AMD may even be able to rival Nvidia's best desktop GPUs with its Navi 32 cards. But where are the desktop equivalents?

Read more
Here’s how Nvidia defends its RTX 4060 Ti’s memory controversy
nvidia rtx 4060 ti 8gb 16gb memory controversy nvidia02

The rumors are true: Nvidia has two versions of its new RTX 4060 Ti graphics card. These are the highly anticipated new midrange GPUs, and yes, one comes with 8GB of VRAM and one comes with 16GB -- and they're separated by $100 in price.

It's a head-scratching decision on a few different levels. Games that demand more than 8GB of VRAM are increasingly common, which is frustrating for those eying the $399 8GB model. What's more -- the RTX 4070 Ti comes with just 12GB of VRAM, despite costing $599.

Read more
Nvidia is serving up a major price cut on its best GPU
Nvidia GeForce RTX 4090 GPU.

Good news -- Nvidia has just lowered the price of its best graphics card. There are some caveats, though. The price adjustment for the RTX 4090 is only happening in Europe, and only the Founders Edition GPU is affected.

In total, the RTX 4090 is now 9.2% cheaper than it was upon launch. Is Nvidia suddenly feeling generous?

Read more