Junglewise Threat Intelligence

CVE-2026-24191: NVIDIA Display Driver TOCTOU race condition in Windows

CVE-2026-24191 · Severity: high · CVSS 7.8 · Published 2026-05-26

Technologies: Nvidia Display Driver. Vendors: Nvidia.

Executive brief

The NVIDIA Display Driver for Windows contains a security flaw that could allow a user already on the system to gain higher levels of access. This driver is essential software that allows the Windows operating system to communicate with NVIDIA graphics hardware. If exploited, an attacker could potentially take full control of the computer, access sensitive data, or cause the system to crash.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability (CWE-367) exists in the NVIDIA Display Driver for Windows. An attacker with local user access can exploit this race condition during the driver's validation of a resource, modifying the resource after it has been checked but before it is used. Successful exploitation requires high attack complexity due to the timing requirements but can result in a scope cross (S:C), allowing for local privilege escalation, arbitrary code execution, information disclosure, or denial of service. Users are advised to refer to NVIDIA advisory 5821 for specific driver version updates and patches.

Affected products

  • NVIDIA Display Driver for Windows

Timeline

  • 2026-05-26: disclosed: Initial publication of the CVE record and NVD entry.

References

Related threats