CVE-2019-5688
NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Prueba de concepto en GitHub (no verificada) · Lista de pruebas de concepto en GitHub
⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.
Tecnologías afectadas (3)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-5688",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@nvidia.com",
"affectedData": [
{
"vendor": "NVIDIA",
"product": "NVIDIA NVFlash, NVUFlash, GPUModeSwitch Tool",
"versions": [
{
"status": "affected",
"version": "NVFlash"
},
{
"status": "affected",
"version": "NVUFlash prior to v5.588.0"
},
{
"status": "affected",
"version": "GPUModeSwitch prior to 2019-11"
}
]
}
]
}
],
"published": "2019-11-18T18:15:10.057",
"references": [
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/4928",
"tags": [
"Vendor Advisory"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/4928",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service."
},
{
"lang": "es",
"value": "NVIDIA NVFlash, NVUFlash Tool versiones anteriores a v5.588.0 y GPUModeSwitch Tool versiones anteriores a 2019-11, el controlador de modo kernel de NVIDIA (nvflash.sys, nvflsh32.sys y nvflsh64.sys) contiene una vulnerabilidad en la cual los usuarios autenticados con privilegios administrativos pueden conseguir acceso a la memoria del dispositivo y los registros de otros dispositivos no administrados por NVIDIA, lo que puede conllevar a una escalada de privilegios, divulgación de información o denegación de servicio."
}
],
"lastModified": "2026-06-17T02:38:04.337",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nvidia:gpumodeswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D43AF9D0-CEBA-4C32-946C-374E49DCC703",
"versionEndExcluding": "2019-11"
},
{
"criteria": "cpe:2.3:a:nvidia:nvflash:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7C96214-BEA4-4C93-8FE2-6EA6CC0A3340",
"versionEndExcluding": "5.588.0"
},
{
"criteria": "cpe:2.3:a:nvidia:nvuflash:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C0B76F8-93FF-481F-9BF8-96BFC1A97108",
"versionEndExcluding": "5.588.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@nvidia.com"
}