vendor:
GeForce Experience
by:
David Yesland
7.8
CVSS
HIGH
OS command injection
78
CWE
Product Name: GeForce Experience
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2019-5678
CPE:
Platforms Tested: Web browsers
2019
POC for CVE-2019-5678 Nvidia GeForce Experience OS command injection via a web browser
This proof-of-concept (POC) demonstrates a vulnerability in Nvidia GeForce Experience that allows an attacker to execute arbitrary OS commands via a web browser. The vulnerability exists in the autoGFEInstall endpoint, which is accessible without authentication. The endpoint accepts a parameter containing the command to be executed, which is then passed to a system call. An attacker can exploit this vulnerability by sending a specially crafted request to the endpoint, which will execute the command specified in the request.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Nvidia GeForce Experience.