motherboards
+ Reply to Thread
Results 1 to 4 of 4

Thread: NVIDIA Display Driver Service Attack Found

  1. #1
    Regular Member

    Status
    xelosia is online now

    Last Online
    Today @ 03:16
    Join Date
    May 2012
    Location
    Windsor Ontario
    Posts
    823
    CPU: AMD FX 6100
    M/B: ASUS CROSSHAIR V
    RAM: 16 gig Corsair Vengence 9- 9- 9 -27 12800 1600 mhz
    GPU: ASUS EAH 6850 1 gig
    • xelosia's Full Spec's
      • Case:
      • Corsair 600T
      • PSU:
      • OCZ ZS 750 watt
      • Cooling:
      • Corsair H60
      • Sound:
      • On Board SB output to a Pioneer VSX906S Reciever
      • Monitor:
      • Sharp 32Inch lcd
      • OS:
      • Windows 7 Home Premium sp1
      • Misc:
      • Lite on Blue Ray CM Sentinel Zero G Mouse
    Thanks
    41
    Thanked 153 Times in 121 Posts
    Points: 6,343, Level: 23
    Points: 6,343, Level: 23
    Level completed: 59%,
    Points required for next Level: 207
    Level completed: 59%, Points required for next Level: 207
    Overall activity: 38.0%
    Overall activity: 38.0%

    Default NVIDIA Display Driver Service Attack Found

    There’s nothing like a zero-day to ruin the holiday break, but that’s just what may be in store for engineers at Nvidia after a researcher discovered a new vulnerability in the Nvidia Display Driver Service. The flaw could hand over administrator privileges on Windows machines to an attacker.Peter Winter-Smith, formerly with the NGS Software of the U.K., posted details of the vulnerability and exploit to Pastebin. In it, he explains that the service is vulnerable to a stack buffer overflow that bypasses data execution prevention (DEP) and address space layout randomization (ASLR) running in the Windows operating system since Windows Vista.
    “The service listens on a named pipe (\pipe\nsvr) which has a NULL DACL configured, which should mean that any logged on user or remote user in a domain context (Windows firewall/file sharing permitting) should be able to exploit this vulnerability,” Winter-Smith wrote on Pastebin. “The buffer overflow occurs as a result of a bad memmove operation.”

    Winter-Smith told Threatpost the vulnerability is difficult to exploit because it mostly affects domain-based machine, and the machines in question would have to have relaxed firewall rules and need to be able to share files.
    “In the local scenario in which an attacker attempts to gain increased privileges on a machine they already have access to, it would be very easy,” Winter-Smith said. “It's not incredibly serious (compared to—say--a browser exploit). If it were going to put people at risk I'd not have released exploit code and I'd have informed the vendor and kept quiet until a fix were issued.”
    Winter-Smith said an attacker could exploit the vulnerability in two ways: with local access they could escalate privileges to root giving them full control over the machine; or remotely against machines on the same Windows domain if the user running Nvidia has enabled file sharing from their machine or has disabled their firewall, remote access can be gained.
    Memmove operations copy data from a source location to a memory destination. Winter-Smith said the service copies data unchecked; an attacker would be able to control the source location as well as the number of bytes copied into the response buffer; an attacker would be able to leak data from the stack by overflowing it.
    “The memmove function copies data from one place in memory to another, and the fact that it was not properly used allowed me to both copy data critical to bypassing the Windows protections,” Winter-Smith said, “by copying private data in memory within the Nvidia service process into the data buffer that would be sent back to me, and trigger the vulnerability (by overwriting memory sufficient to give me full control over what the Nvidia service would try to do once the processing of my messages had completed).”
    Nvidia, based in Santa Clara, Calif., builds graphics processing units for PCs, mobile and embedded devices, as well as other processing applications for high-performance computing systems. Nvidia competes with Intel, AMD and Qualcomm in these markets. The nvsvc32.exe service in question here runs automatically on any Windows machine running a Nvidia GPU.
    Winter-Smith said he wanted to share the exploit in a timely fashion, rather than report it.
    “I am definitely not averse to responsible disclosure and typically do follow a responsible disclosure process, however the risk from this particular flaw being exploited was (is) sufficiently low that I didn't think it would warrant the wait,” he said.


    https://threatpost.com/en_us/blogs/n...achines-122712

  2. #2
    Regular Member

    Status
    Adham is offline

    Last Online
    22-05-2013 @ 03:16
    Join Date
    Jul 2012
    Location
    México
    Posts
    567
    CPU: Semprom LE-1250
    M/B: Sapphire Tech. LTD. PE-AM2RS690MH (Socket AM2 )
    RAM: 3GB kingston 1024 MBytes
    GPU: 1024MBGeForce GT 220 (PNY)
    • Adham's Full Spec's
      • Case:
      • dunno what brand is it >_<
      • PSU:
      • RAID MAX ATX12V POWER
      • Cooling:
      • no cooling
      • Sound:
      • Realtek High Definition Audio
      • Monitor:
      • BenQ G900W (1440x900@60Hz)
      • OS:
      • Windoes Seven home edition
      • Misc:
      • my pc is kinda old... and i dont have cooling system and dont know the brand of my case
    Thanks
    27
    Thanked 26 Times in 24 Posts
    Points: 1,251, Level: 9
    Points: 1,251, Level: 9
    Level completed: 51%,
    Points required for next Level: 99
    Level completed: 51%, Points required for next Level: 99
    Overall activity: 32.0%
    Overall activity: 32.0%

    Default Re: NVIDIA Display Driver Service Attack Found

    HOLLY, thats bad, brb uninstalling it lol

  3. #3
    OC Droid

    Status
    Doctor_Death is offline

    Last Online
    Yesterday @ 19:13
    Join Date
    Apr 2008
    Location
    Punxsutawney, Pa. - USA
    Posts
    10,263
    CPU: Core i7 3930K
    M/B: ASRock X79 Extreme9
    RAM: 64GBs Kingston Beast 2133MHz
    GPU: Two EVGA GTX 690s
    • Doctor_Death's Full Spec's
      • Case:
      • CM Cosmos II Ultra
      • PSU:
      • CM Silent Pro Hybrid Corsair AX120oi
      • Cooling:
      • Corsair H110
      • Sound:
      • On Board
      • Monitor:
      • Dell U3011 30" widescreen LCD with 2560 x 1600 Resolution
      • OS:
      • Win 7 Ultimate
      • Misc:
      • Asus Blu-Ray, Asus 24X DVD Burner, MS Sidewinder X4 Keyboard / Razer Abyssus Mouse/ Razer eXact Mat
    Thanks
    305
    Thanked 1,658 Times in 1,264 Posts
    Points: 61,396, Level: 76
    Points: 61,396, Level: 76
    Level completed: 85%,
    Points required for next Level: 254
    Level completed: 85%, Points required for next Level: 254
    Overall activity: 99.7%
    Overall activity: 99.7%

    Default Re: NVIDIA Display Driver Service Attack Found

    People are idiots posting this crap, nothing like letting the attackers know what's going on so they screw over millions of people.
    2nd system

    ASRock Z77 OC Formula, 2700K, Two EVGA GTX680s, and one GTX660 Ti PE, 16GBs 2133MHz, Lian Li A75X , Maxrevo 1500W, TT Extreme 240

    3rd system

    ASUS ROG X79 Rampage 4 Formula, 3930K, Boreas Chiller, VisionTek 480GB, WD 750GB, 16GBs Kingston HyperX Red 1600MHz, Two GTX680s, OCZ 1250W, CM Stryker modded for the Boreas Chiller, 3 white Skull fans grills from MNPCTech.
    .

  4. #4
    Regular Member

    Status
    Cyberburnout is offline

    Last Online
    13-05-2013 @ 08:22
    Join Date
    Jul 2012
    Location
    GROVE CITY OHIO
    Posts
    1,317
    CPU: Phenom X4 965BE @3.8ghz
    M/B: ASrock 970de3/u3s3
    RAM: 16GB Corsair Dominator Platinum
    GPU: MSI 660TI Power Edition
    • Cyberburnout's Full Spec's
      • Case:
      • Switch 810 Matte
      • PSU:
      • OCZ 700W
      • Cooling:
      • Cooler Master 212 evo w/extra Sickleflow 120 in push-pull. 2 x Cougar Vortex HDB 120mm (1 front + 1 rear)
      • Sound:
      • ONBOARD
      • Monitor:
      • lG 55in lcd TV
      • OS:
      • WINDOWS 7 ULTIMATE X64
    Thanks
    40
    Thanked 110 Times in 100 Posts
    Points: 4,134, Level: 18
    Points: 4,134, Level: 18
    Level completed: 72%,
    Points required for next Level: 116
    Level completed: 72%, Points required for next Level: 116
    Overall activity: 17.0%
    Overall activity: 17.0%

    Default Re: NVIDIA Display Driver Service Attack Found

    Quote Originally Posted by Doctor_Death View Post
    People are idiots posting this crap, nothing like letting the attackers know what's going on so they screw over millions of people.
    There are two reason why this information is posted. 1.because they are like you described, Idiots. They want recognition for finding the exploit. 2. To make sure the hole is fixed. It will take a bit of time before a hacker can figure out a viable way to exploit the vulnerabilities and get it packaged for mass delivery. The software maker has time to fix the hole and roll out updates. Usually when you see these published the software maker is already informed and given a little time before it has been published.

    All of this started because it came to light that some software makers were well aware of vulnerabilities but were not fixing them until after hackers were already ripping users ass. The biggest was Microsoft a couple years back, being aware of a massive hole but didn't fix it for 18 months after they knew, and months after hacks were coming out. Apple had a similar issue. Dont forget about Adobe and its zero day exploit problems.

    So im glad these get published, it forces them to actually fix the damn problems instead of hiding them.
    Any sufficiently advanced technology is indistinguishable from magic.......... Arthur C. Clarke
    A+ Certified. Dell, Lenovo, HP, Lexmarks, Xerox, Panasonic and NEC Certified ASP.

+ Reply to Thread

Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Similar Threads

  1. Replies: 0
    Last Post: 11-10-2012, 14:31
  2. Nvidia 295.73 driver does not have the currnet physx driver
    By Juggalo23451 in forum Graphics Cards
    Replies: 1
    Last Post: 21-02-2012, 15:47
  3. new nvidia driver is out
    By aryan51 in forum Graphics Cards
    Replies: 8
    Last Post: 21-02-2012, 13:11
  4. Display driver has stopped responding
    By Geralt in forum Graphics Cards
    Replies: 6
    Last Post: 12-08-2008, 00:20
  5. AMD to challenge Nvidia on the driver front, too
    By News Team in forum Hardware News
    Replies: 0
    Last Post: 05-08-2008, 09:13

Search tags for this page

stopping the nvidia display driver service

Click on a term to search for related topics.

Tags for this Thread