fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

NVIDIA Fixes Code Execution Bug In GeForce Experience Software

NVIDIA Fixes Code Execution Bug In GeForce Experience Software

NVIDIA fixes code execution bug in GeForce Experience software

NVIDIA has addressed a vulnerability in the Windows NVIDIA GeForce Experience (GFE) software that could allow local attackers to execute arbitrary code, trigger a denial of service (DoS) state, or access privileged information on unpatched systems.

Even though the security flaw tracked as CVE‑2020‑5964 requires attackers to have local user access to the device and cannot be exploited remotely, it can still be abused with the help of malicious tools delivered to systems running vulnerable NVIDIA GFE versions.

NVIDIA GeForce Experience is the companion software for GeForce GTX, RTX, TITAN X, and other NVIDIA GeForce graphics cards, and it can be installed on computers running Windows 7 or later.

It “keeps your drivers up to date, automatically optimizes your game settings, and gives you the easiest way to share your greatest gaming moments with friends” according to NVIDIA,

Also read: 4 easy guides to data breach assessment

Security issue rated as medium severity

After successfully exploiting the CVE‑2020‑5964 flaw could enable attackers could execute arbitrary code on Windows machines running unpatched NVIDIA GFE software versions.

They could also gain access to sensitive information beyond the permissions initially granted by the compromised system or render them unusable by triggering a denial of service state.

The CVE‑2020‑5964 vulnerability fixed as part of the July 2020 security update is detailed below, together with a full description and the CVSS V3 base score assigned by NVIDIA.

CVE IDDescriptionBase ScoreVector
CVE‑2020‑5964NVIDIA GeForce Experience software contains a vulnerability in the service host component, in which the integrity check of application resources may be missed. Such an attack may lead to code execution, denial of service, or information disclosure.6.5AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

NVIDIA says that the “risk assessment is based on an average of risk across a diverse set of installed systems and may not represent the true risk of your local installation.

The company also advises “consulting a security or IT professional to evaluate the risk to your specific configuration.”

Affected NVIDIA GeForce Experience versions

The security issue impacts Windows computers running versions of NVIDIA GeForce Experience before 3.20.4.

“Earlier software branch releases that support this product are also affected,” NVIDIA also explained. “If you are using an earlier branch release, upgrade to the latest branch release.”

To apply the security update, NVIDIA GeForce Experience users can download the latest software version from the GeForce Experience Downloads page or launch the GFE client on their Windows computers to have it applied using the built-in automatic update mechanism.

NVIDIA GFE update

Also read: Privacy policy template important tips for your business

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us