Threat Advisory

NVIDIA ChatRTX Windows Vulnerability Enables Privilege Escalation

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical security flaw from NVIDIA for its Windows ChatRTX application has disclosed several vulnerabilities that could be exploited by attackers, posing serious risks to users and organizations. These vulnerabilities, identified as CVE-2024-0096, CVE-2024-0097, and CVE-2024-0098, include high severity issues such as improper privilege management within the ChatRTX UI, leading to escalated privileges, data tampering, and unauthorized access to sensitive information. CVE-2024-0096 involves user inputs altering execution flow, potentially leading to information disclosure, while CVE-2024-0097 is triggered by interprocess communication flaws, posing similar risks. CVE-2024-0098, with a medium involves the clear-text transmission of sensitive information within the ChatRTX UI and backend. NVIDIA has promptly responded with a software update to address these vulnerabilities, urging users to install it promptly. These efforts are part of NVIDIA's ongoing commitment to potential misuse that could compromise user data or system integrity.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical security flaw from NVIDIA for its Windows ChatRTX application has disclosed several vulnerabilities that could be exploited by attackers, posing serious risks to users and organizations. These vulnerabilities, identified as CVE-2024-0096, CVE-2024-0097, and CVE-2024-0098, include high severity issues such as improper privilege management within the ChatRTX UI, leading to escalated privileges, data tampering, and unauthorized access to sensitive information. CVE-2024-0096 involves user inputs altering execution flow, potentially leading to information disclosure, while CVE-2024-0097 is triggered by interprocess communication flaws, posing similar risks. CVE-2024-0098, with a medium involves the clear-text transmission of sensitive information within the ChatRTX UI and backend. NVIDIA has promptly responded with a software update to address these vulnerabilities, urging users to install it promptly. These efforts are part of NVIDIA's ongoing commitment to potential misuse that could compromise user data or system integrity.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update NVIDIA ChatRTX to version 0.3

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/nvidia-chatrtx-windows-vulnerability/

[/emaillocker]
crossmenu