Spoofing attack vulnerability in Geforce Experience - CVE-2021-1073ID: oval:org.secpod.oval:def:84719 | Date: (C)2022-10-11 (M)2022-11-23 |
Class: VULNERABILITY | Family: windows |
The host is installed with Geforce Experience prior to 3.23 and is prone to a spoofing attack vulnerability. A flaw is present in the application, which fails to properly handle special formatted links. Successful exploitation allows remote attackers can create a specially crafted link that opens the GeForce Experience login page in a new browser tab instead of the GeForce Experience application and enters their login information, the malicious site can get access to the token of the user login session.
Platform: |
Microsoft Windows 10 |
Microsoft Windows 7 |
Microsoft Windows 8 |
Microsoft Windows 8.1 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2019 |
Microsoft Windows 11 |
Microsoft Windows Server 2022 |
Product: |
Nvidia Geforce Experience |