← Vulnerability feed

Vulnerability record · CVE-2021-23175 · published 23 December 2021

CVE-2021-23175: Nvidia geforce experience incorrect authorization vulnerability

Nvidia · Geforce Experience

NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.

8.2 CVSS 3.1 High EPSS 0.45% · top 63.5% CWE-863 · Incorrect authorization
8.2CVSS 3.1 base score, v2 4.4
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23175 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed8.8CVE-2017-6250Nvidia geforce experience vulnerabilityNVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application ex…EPSS 0.35%8.8CVE-2016-8812Nvidia geforce experience memory buffer overflow vulnerabilityFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulner…EPSS 1.6%8.3CVE-2021-1073Nvidia geforce experience vulnerabilityNVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, whi…EPSS 0.90%7.8CVE-2022-42292Nvidia geforce experience link following vulnerabilityNVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic …EPSS 0.18%7.8CVE-2020-5990Nvidia geforce experience vulnerabilityNVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which may lead to local privilege es…EPSS 0.38%7.8CVE-2020-5977Nvidia geforce experience untrusted search path vulnerabilityNVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled …EPSS 0.43%7.8CVE-2020-5978Nvidia geforce experience vulnerabilityNVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in its services in which a folder is created by nvcontainer.exe …EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2021-23175), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.