CVE-2019-5676: NVIDIA Geforce Experience

Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.

Affected products

  • NVIDIA Geforce Experience: before 3.19 (fixed in 3.19)
  • NVIDIA GPU Display Driver: from 410, before 412.36 (fixed in 412.36); from 418, before 425.51 (fixed in 425.51); from 430, before 430.64 (fixed in 430.64)

Published 2019-05-10. Last modified 2026-06-17.