CVE-2022-31611 MEDIUM

CVE-2022-31611

Vendor Nvidia
Product GeForce Experience
Weakness CWE-427
Published February 7, 2023
Last update March 25, 2025

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H

What the vulnerability does

01Description

NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileges may cause the installer to load an arbitrary DLL when the installer is launched. A successful exploit of this vulnerability could lead to escalation of privileges and code execution.

Key dates

02Disclosure timeline

February 7, 2023 CVE published
March 25, 2025 Record updated