Security flaw in nVidia display drivers fixed

By on January 6, 2013 11:58:31 AM from JoeUser Forums JoeUser Forums

DrJBHL

Join Date 04/2002
+2123

 

Apparently, drivers using the nvvsvc.exe belonging to the NVIDIA Driver Helper Service installed with the driver is the one affected with the security flaw.

The flaw allows elevation of privileges and can be used to access sensitive data on your system. Mostly affected/targeted are businesses using the driver, but all systems with the helper service are affected and need updating.

Until now, the work around has been to turn off/disable the helper service. Now a new GeForce driver has been developed and released and is named 310.90 WHQL (Windows Hardware Quality Labs) since MS’s labs have been involved in testing the new driver which is digitally signed.

Interestingly, the new driver is reported by gHacks.net to improve performance for Black Ops 2 and Assassin’s Creed III.

gHacks reports:

“It is highly recommended to select custom installation to avoid the installation of drivers and software that you do not make use of on your PC. Check out this overview of NVIDIA driver components to find out which drivers you need to install and which you may not need at all.

There you also find a solution to block the two processes nvvsvc.exe and nvxdsync.exe from running all the time on the system. You may have noticed that one of them is the process that has been vulnerable to the exploit.

It is highly recommended to install the NVIDIA GeForce driver update as quickly as possible on vulnerable systems to protect them from attacks and the exploit.”

Together with that:

1. It is highly recommended you create a restore point and a backup before installing the new drivers, or any software for that matter.

2. Read what nVidia writes about the driver on the download page. Specific OEM’s like Sony and Dell have specific firmware which is preferable to the regular nVidia driver. You should check out your specific model at the OEM’s website. If in doubt, pm someone of yrag’s skill and knowledge level. Also, contact the OEM’s Tech Support.

3. Read more about which components to install here:  http://www.ghacks.net/2012/12/26/make-sure-you-only-install-nvidia-drivers-you-need/

4. Please do your own research on the topic. If you find something significant please add it to the thread.

 

Source:

http://www.ghacks.net/2013/01/06/nvidia-geforce-310-90-driver-update-fixes-security-vulnerability/?_m=3n%2e0038%2e755%2ehj0ao01hy5%2erxc

4 Replies
Search this post
Subscription Options


Reason for Karma (Optional)
Successfully updated karma reason!
January 6, 2013 1:16:05 PM from WinCustomize Forums WinCustomize Forums

Yep! Installed the update today!

Reason for Karma (Optional)
Successfully updated karma reason!
January 6, 2013 1:37:35 PM from WinCustomize Forums WinCustomize Forums

I got it a week or so ago, when I installed the new GFX card. 

 

Oops, I have 310.70 

Reason for Karma (Optional)
Successfully updated karma reason!
January 6, 2013 2:10:27 PM from WinCustomize Forums WinCustomize Forums

Sony Tech Support was absolutely no help. "Stay tuned, visit the esupport page."

They maintained that 310.90 might not plug up the issue... After asking me what it's all about. Uh-huh. 

Lucky I was wearing my waders.

Surprise.... not.

Reason for Karma (Optional)
Successfully updated karma reason!
Sign Up or Login and this ad disappears!
There are many great features available to you once you register. Sign Up for a free account and browse the forums without ads.
January 6, 2013 8:41:46 PM from WinCustomize Forums WinCustomize Forums

I installed 310.90 today, so hopefully I'm safe.

Reason for Karma (Optional)
Successfully updated karma reason!
Stardock Forums v1.0.0.0    #108431  walnut1   Server Load Time: 00:00:00.0000078   Page Render Time:

Home | About | Privacy | Upload Guidelines | Terms of Service | Help
WinCustomize © 2014 Stardock Corporation. All Rights Reserved.