Nvidia Zero-Day Exploit Discovered: GreenSection Allows Memory Corruption
Nvidia's user-mode components have been hit by a new zero-day exploit dubbed GreenSection. The vulnerability, discovered by security researcher Chaotic Eclipse, allows attackers to corrupt memory and potentially gain SYSTEM-level privileges.
The researcher notes that the flaw does not immediately provide SYSTEM-level privileges but could allow an attacker to cross user boundaries or compromise the Windows Desktop Window Manager (dwm.exe) process. A simple proof-of-concept has been provided, which can be run on an application using Vulkan or OpenGL and triggers a crash.
Chaotic Eclipse is known for releasing PoC exploits for zero-day vulnerabilities and has previously targeted Microsoft products, including Windows and Microsoft Defender. The researcher's work has sparked debate over responsible disclosure and the risks of publishing working exploits.