CVE-2026-24191
Received Received - Intake
NVIDIA Display Driver TOCTOU Vulnerability

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: NVIDIA Corporation

Description
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-05-26
AI Q&A
2026-05-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nvidia display_driver *
nvidia display_driver From 7.8 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-24191 is a vulnerability in the NVIDIA Display Driver for Windows that involves a time-of-check time-of-use (TOCTOU) issue. This type of vulnerability occurs when there is a race condition between checking a condition and using the result of that check, which can be exploited by an attacker.

A successful exploit of this vulnerability could allow an attacker to cause denial of service, escalate privileges, disclose sensitive information, tamper with data, or execute arbitrary code on the affected system.


How can this vulnerability impact me? :

This vulnerability can have serious impacts including:

  • Denial of Service (DoS) - causing the system or driver to become unavailable.
  • Escalation of Privileges - allowing an attacker with limited access to gain higher privileges.
  • Information Disclosure - exposing sensitive data to unauthorized parties.
  • Data Tampering - unauthorized modification of data.
  • Code Execution - running arbitrary code, potentially leading to full system compromise.

Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart