Cyber Affairs
No Result
View All Result
  • Login
  • Register
[gtranslate]
  • Home
  • Live Threat Map
  • Books
  • Careers
  • Latest
  • Podcast
  • Popular
  • Press Release
  • Reports
  • Tech Indexes
  • White Papers
  • Contact
Social icon element need JNews Essential plugin to be activated.
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
COMMUNITY
NEWSLETTER
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
NEWSLETTER
No Result
View All Result
Cyber Affairs
No Result
View All Result
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

NVIDIA ChatRTX For Windows App Vulnerability

admin by admin
Mar 28, 2024
in News
A A
0

A security update released by ChatRTX on March 26th, 2024, addresses two vulnerabilities (CVE-2024-0082 and CVE-2024-0083) that could allow attackers to execute malicious code and tamper with data on affected systems. 

The vulnerabilities stem from improper input validation (CWE-20) and improper privilege management (CWE-269) practices, where attackers could potentially trick the system into running unintended code or gain access to unauthorized data. 

The Common Vulnerability Scoring System (CVSS v3.1) assigns a high-risk severity score (8.2) to these vulnerabilities, highlighting the importance of updating to the latest version of ChatRTX to mitigate these risks.

An attacker can exploit a vulnerability in NVIDIA ChatRTX for Windows to potentially escalate their privileges, leak sensitive information, or tamper with data on a vulnerable system. 

Sending specially crafted open file requests can trigger this vulnerability, which is present in the application’s user interface (UI). The exploitability of this vulnerability is rated as low complexity, which can be easily carried out. 

It also requires low privileges on the attacker’s part, further increasing the exploitability wherever a successful exploit could result in a complete compromise of the system, as the attacker would gain full control, reads the advisory.

The vulnerability has a high potential impact due to the severity of the potential consequences and the overall severity rating of this vulnerability is also high (8.2), which falls under CWE-269, a category of weaknesses known as improper privilege management.

Revision History

A critical vulnerability (CVE-2024-0083) exists in NVIDIA ChatRTX for Windows that allows attackers to inject malicious scripts into users’ browsers via a cross-site scripting (XSS) flaw in the UI. 

It could potentially enable attackers to execute arbitrary code on the victim’s machine, cause denial-of-service by crashing the application, or steal sensitive information. 

The vulnerability is rated medium severity due to the lack of a complete remote code execution exploit, but it still presents a significant risk.

NVIDIA’s general risk assessment might not accurately reflect the system’s vulnerability due to variations in installed components.

To ensure proper security posture, NVIDIA advises evaluating the specific risks associated with the unique system configuration. 

There is a security update for NVIDIA ChatRTX software for Windows that addresses vulnerabilities (CVE-2024-0082, CVE-2024-0083) in all versions prior to 0.2. 

Updated list

To install the update, download the ChatWithRTX_installer_3_5.zip file from the ChatRTX Download page and be aware that both the affected version and the updated version are labeled as 0.2. 

Also verify that the downloaded file is named ChatWithRTX_installer_3_5.zip to ensure the updated version. 

The document was initially released on March 26, 2024, with version 1.0, whose history log serves as a record of changes made to the document over time, allowing for comparison and rollback to previous versions if necessary.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.



Read the full article here

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

[mc4wp_form id=”387″]

Recent News

  • Understanding the Implications & Guarding Privacy- Axios Security Group
  • Hackers Actively Using Pupy RAT to Attack Linux Systems
  • Buckle Up_ BEC and VEC Attacks Target Automotive Industry

Topics

  • AI
  • Books
  • Careers
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • News
  • Podcast
  • Reports
  • Tech Indexes
  • Uncategorized
  • White Papers

Get Informed

[mc4wp_form id=”387″]

Social icon element need JNews Essential plugin to be activated.

Copyright © 2022 Cyber Affairs. All rights reserved.

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Copyright © 2022 Cyber Affairs. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.