solution Contentsolution Content

SUPPORT COMMUNICATION- SECURITY BULLETIN

Document ID: c06271500

Version: 2

HPSBHF03611 rev. 2 - NVIDIA GPU Display Driver Vulnerabilities

Notice: The information in this security bulletin should be acted upon as soon as possible.

Release date : 21-Mar-2019

Last updated : 31-Oct-2019

Potential Security Impact:
Denial of service, Escalation of privilege, Unauthorized code execution, or Information disclosure
Source: HP, HP Product Security Response Team (PSRT)
Reported By: NVIDIA

VULNERABILITY SUMMARY
HP has been notified of potential security vulnerabilities with the GPU Display Driver for certain NVIDIA products. These vulnerabilities may lead to denial of service, escalation of privileges, unauthorized code execution, or information disclosure.
Reference Number
CVE-2019-5665, CVE-2019-5666, CVE-2019-5667, CVE-2019-5668, CVE-2019-5669, CVE-2019-5670, CVE-2019-5671, CVE-2018-6260, NVIDIA Security Bulletin 4772 (in English), PSR-2019-0058
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
See RESOLUTION section below
BACKGROUND
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com
CVSS 3.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2019-5665
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
8.8
CVE-2019-5666
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
8.8
CVE-2019-5667
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
8.8
CVE-2019-5668
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
8.8
CVE-2019-5669
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
8.8
CVE-2019-5670
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2019-5671
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
6.5
CVE-2018-6260
AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
2.2
RESOLUTION
HP has identified the affected products and target dates for Softpaqs. See the affected products listed below.
note:
This bulletin will be updated. Check back frequently for updates. HP recommends keeping your system up to date with the latest firmware and software.

How do I know if I am impacted?

  1. Launch Windows Device Manager.
  2. Select Display Adapters.
  3. If you see a node with one of the NVIDIA products listed below, then verify the driver version.

How do I know the driver version I have installed?

  1. Launch Windows Device Manager.
  2. Select Display Adapters.
  3. Select the NVIDIA product node and right-click.
  4. Go to the Driver tab.
  5. If you have an earlier driver version, then update the driver using the link for your product below.
The driver version can be identified by the last digits of the version number.
For example: 10.18.13.6472 is 364.72 and 10.18.13.472 is 304.72.
Pending: Softpaq is in progress.
Under investigation: System under investigation for impact, or Softpaq under investigation for feasibility/availability.
Not available: Softpaq not available due to technical or logistical constraints.

Business PCs and Retail Point-of-Sale systems

Product
Driver Version
Softpaq ID
NVS510
419.01 (Win10)
NVS510
419.01 (Win7 Win8.1 64 bit)
GF GT630
419.01 (Win10)
GF GT630
419.01 (Win7 Win8.1 64 bit)
GF GT730
419.01 (Win10)
GF GT730
419.01 (Win7 Win8.1 64 bit)
GF GT730A
419.01 (Win10)
GF GT730A
419.01 (Win7 Win8.1 64 bit)
GT720
419.01 (Win10)
GT720
419.01 (Win7 Win8.1 64 bit)
GTX960
419.01 (Win10)
GTX960
419.01 (Win7 Win8.1 64 bit)
Quadro K620
419.01 (Win10)
Quadro K620
419.01 (Win7 Win8.1 64 bit)
Quadro P620
419.01 (Win10)
Quadro P620
419.01 (Win7 Win8.1 64 bit)
GTX1080
419.01 (Win10)
GTX1080
419.01 (Win7 Win8.1 64 bit)
GTX1070-B
419.01 (Win10)
GTX1070-B
419.01 (Win7 Win8.1 64 bit)
GTX1060-B
419.01 (Win10)
GTX1060-B
419.01 (Win7 Win8.1 64 bit)
RTX2080
419.01 (Win10)
Quadro P400
419.01 (Win10)
Quadro P400
419.01 (Win7 Win8.1 64 bit)
NVS310 1GB
392.37(Win10)
NVS310 1GB
392.37(Win7 Win8.1 64 bit)
NVS310 1GB
392.37(Win7 Win8.1 32 bit)
NVS310 512MB
392.37(Win10)
NVS310 512MB
392.37(Win7 Win8.1 64 bit)
NVS310 512MB
392.37(Win7 Win8.1 32 bit)
NVS315
392.37(Win10)
NVS315
392.37(Win7 Win8.1 64 bit)
NVS315
392.37(Win7 Win8.1 32 bit)
NVS510
392.37(Win7 Win8.1 32 bit)
GF GT630
392.37(Win7 Win8.1 32 bit)
GF GT730
392.37(Win7 Win8.1 32 bit)
GT720
392.37(Win7 Win8.1 32 bit)
GTX960
392.37(Win7 Win8.1 32 bit)
GT730
392.37(Win7 Win8.1 32 bit)
GTX1080
392.37(Win7 Win8.1 32 bit)
GTX1060-B
392.37(Win7 Win8.1 32 bit)
GTX1070-B
392.37(Win7 Win8.1 32 bit)
Quadro P400
392.37(Win7 Win8.1 32 bit)
Quadro K620
392.37(Win7 Win8.1 32 bit)
Quadro P620
392.37(Win7 Win8.1 32 bit)
Nvidia N15P-Q1 (Nvidia Quadro K1100M)
425.91
Nvidia N15P-Q5 (Nvidia Quadro K2200M)
425.91
Nvidia N15E-Q1 (Nvidia Quadro K3100M)
425.91
Nvidia N15E-Q3 (Nvidia Quadro K4100M)
425.91
Nvidia N15E-Q5 (Nvidia Quadro K5100M)
425.91
Nvidia N17P-Q1 (Nvidia Quadro M1200)
425.53
Nvidia N17P-Q3 (Nvidia Quadro M2200)
425.53
Nvidia N17E-Q1 (Nvidia Quadro P3000)
425.53
Nvidia N17E-Q3 (Nvidia Quadro P4000)
425.53
Nvidia N17E-Q5 (Nvidia Quadro P5000)
425.53
Nvidia N15M-Q2 (Nvidia Quadro K610M)
425.91
Nvidia N16P-Q1 (Nvidia Quadro M1000M)
425.53
Nvidia N16P-Q3 (Nvidia Quadro M2000M)
425.53
Nvidia N16E-Q1 (Nvidia Quadro M3000M)
425.53
Nvidia N16E-Q3 (Nvidia Quadro M4000M)
425.53
Nvidia N16E-Q5 (Nvidia Quadro M5000M)
425.53
Nvidia N17P-Q1 (Nvidia Quadro M1200M)
425.53
Nvidia N17P-Q3 (Nvidia Quadro M2200M)
425.53
Nvidia N18P-Q1 (Nvidia Quadro P1000)
425.53
Nvidia N18P-Q3 (Nvidia Quadro P2000)
425.53
Nvidia N18P-Q1 (Nvidia Quadro P3000)
425.53
Nvidia N18P-Q1 (Nvidia Quadro P4000)
425.53
Nvidia N18P-Q1 (Nvidia Quadro P5200)
425.53
NVIDIA N17M-Q3 (Nvidia Quadro M620)
425.53
NVIDIA GeForce MX150
425.25
NVIDIA GeForce 930M
425.25
Nvidia N16S-GMR-S (Nvidia GeForce 930MX)
425.25
Nvidia N15P-Q3 (Nvidia Quadro K2100M)
425.91
Nvidia N16M-Q2 (Nvidia Quadro M600M)
425.53
Nvidia GeForce GTX 1050 Max-Q
425.25

Immersive PCs

Product Name
Updated Version
Softpaq #
Softpaq Link
Sprout by HP
25.21.14.1901
SP95242
Sprout Pro by HP
25.21.14.1901
SP95273
Sprout Pro by HP G2
25.21.14.1917
SP95224

Desktop Workstation PCs

Platform list pending.
Product
Driver Version
Softpaq ID
Quadro RTX 8000
419.17
Quadro RTX 6000
419.17
Quadro RTX 5000
419.17
Quadro RTX 4000
419.17
Quadro GV100
419.17
419.17
Quadro GP100
419.17
Quadro P6000
419.17
Quadro P5000
419.17
Quadro P4000
419.17
Quadro P2000
419.17
Quadro P1000
419.17
Quadro P620
419.17
Quadro P600
419.17
Quadro P400
419.17
Quadro M6000 24G
419.17
Quadro M6000
419.17
Quadro M5000
419.17
Quadro M4000
419.17
Quadro M2000
419.17
Quadro M2000M
419.17
Quadro M1000M
419.17
Quadro M620
419.17
Quadro K6000
419.17
Quadro K5200
419.17
Quadro K4200
419.17
ProQuadro K2200
419.17
Quadro K1200
419.17
Quadro K620
419.17
Quadro K420
419.17
Quadro K5000
419.17
Quadro K4000
419.17
Quadro K2000
419.17
Quadro K600
419.17
Quadro K4100M
419.17
Quadro K3100M
419.17
Quadro K2100M
419.17
Quadro K610M
419.17
Quadro K4000M
419.17
Quadro K3000M
419.17
Tesla K40c
419.17
Tesla K20c
419.17
Quadro 410
419.17
NVS 510
419.17

Consumer PCs

note:
NVIDIA Driver Updates for Consumer PCs are available via Windows Update.
Product
Driver Version
SoftPaq ID
N18E-G3 (GeForce RTX 2080)
25.21.14.1788
Not available
N18E-G2 (GeForce RTX 2070)
25.21.14.1788
Not available
N18E-G1 (GeForce GTX 2060 Ti)
25.21.14.1788
Not available
N18E-G0 (GeForce GTX 2060)
25.21.14.1788
Not available
N18P-G0 (GeForce GTX 2050 Ti)
25.21.14.1788
Not available
N18P-G0 (GeForce GTX 2050)
25.21.14.1788
Not available
N17E-G3 (GeForce GTX 1080)
25.21.14.1788
Not available
N17E-G2 (GeForce GTX 1070)
25.21.14.1788
Not available
N17E-G1 (GeForce GTX 1060)
25.21.14.1788
Not available
N17P-G1 (GeForce GTX 1050Ti)
25.21.14.1788
Not available
N17P-G0 (GeForce GTX 1050)
25.21.14.1788
Not available
N17P-G0-K1 (GTX 1050)
25.21.14.1788
Not available
N17S-G2 (GeForce MX250)
25.21.14.1788
Not available
N17S-G1 (GeForce MX150)
25.21.14.1788
Not available
N17S-LG (GeForce MX150)
25.21.14.1788
Not available
N16E-GR (GeForce GTX 965M)
25.21.14.1788
Not available
N16P-GT (GeForce GTX 950M)
25.21.14.1788
Not available
N16P-GX (GeForce GTX 960M)
25.21.14.1788
Not available
N16S-GTR-S (GeForce 940MX)
25.21.14.1788
Not available
N16S-GMR (GeForce 930MX)
25.21.14.1788
Not available
N16S-GM (GeForce 930M)
25.21.14.1788
Not available
N16S-GTR (GeForce MX130)
25.21.14.1788
Not available
N16V-GMR (GeForce MX110)
25.21.14.1788
Not available
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, visit https://www.hp.com/go/contacthp to learn about your HP support options.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp-security-alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via email, visit https://www.hp.com/go/alerts.
Security Bulletin Archive: To view released Security Bulletins, search the HP Support Site for "security bulletin".
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
GN
HP General Software
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version:1 – 21 March 2019 Initial publication. Version:2 - 31 October 2019 Updated remaining SoftPaq URLs

HP Inc. shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. HP Inc. and the names of HP products referenced herein are trademarks of HP Inc. in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.