Here's another good reason to keep your GeForce Experience software up to date

Nvidia RTX 3080 Ti Matrix backplate
(Image credit: Nvidia)

In case you haven't updated to Nvidia's latest GeForce Experience version, now is the time to do so. If you're still on anything older than version 3.27.0.112, your PC could be wide open to certain cybersecurity risks, with the potential for hackers to gain access to your PC via your outdated GeForce Experience software.

The vulnerabilities, as described by the Nvidia development team in a security bulletin (via Hardware Info), include "code execution, information disclosure, data tampering, and denial of service."

Discovered by Minse Kim of Korea University's DNSLab, there are three main attack methods that older GeForce Experience versions leaves users open to. The one that scores highest on the vulnerability scale would involve the user initialising the GeForce Experience install from a compromised directory. Looks like they had to have accidentally deleted something from the install folder first, though. So although it's probably a rare occurrence, it can lead to some serious data tampering.

The second vulnerability would see the hackers using the installer to do their nefarious bidding.

"GeForce Experience contains an uncontrolled search path vulnerability in all its client installers," the bulletin says. In order to exploit this, the hackers would need to have already gained user level privileges, allowing them to use the installer to load an arbitrary DLL. That would allow them to escalate their privileges and execute whatever code they fancied on your PC.

Your next upgrade

(Image credit: Future)

Best CPU for gaming: The top chips from Intel and AMD
Best gaming motherboard: The right boards
Best graphics card: Your perfect pixel-pusher awaits
Best SSD for gaming: Get into the game ahead of the rest

Last but not least, the "NVContainer component" vulnerability would allow a hacker with user level privileges to create a "symbolic link" to a file that needs admin privileges, and sneakily give them an escalation of privilege, opening a window for "denial of service, or limited data tampering." That means removing your access and messing with your machine while you're left to figure out what the heck is going on.

For a software tasked with keeping your graphics card working—i.e. one of the most important softwares on your gaming PC—you'd think we wouldn't have to deal with this. But as many of us will know, software development is never as straightforward as we'd like it to be.

Hackers are constantly evolving, so make sure to keep your software up to date.

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Read more
Nvidia RTX 5080 Founders Edition graphics card from different angles
Latest Nvidia Game Ready drivers fix various black screen issues that left gamers staring at their sad reflections
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Nvidia RTX 5080 Founders Edition graphics card from different angles
Nvidia's latest 572.16 driver isn't just for the RTX 50-series, as 20, 30 and 40-series cards are also gifted with significant updates
MSI RTX 5090 Suprim in an open test bench
RTX 50-series black screen issues should finally be fixed this week in an official Nvidia driver update
Nvidia RTX 5080 Founders Edition graphics card from different angles
Nvidia says it really has sorted RTX 50-series black screen issues this time around as yet another driver fix finds its way to release
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Assassin's Creed Shadows promo image
Ubisoft scores a legendary ratio against Elon Musk on his own platform—which hopefully marks a final end to all the Assassin's Creed Shadows' culture war nonsense
Tzarina Katarin Bokha, the Ice Queen of Kislev
Total War: Warhammer 3 rolls out a cool Kislev overhaul, changes befitting Tzeench’s magic, new projectile units and creakier skeletal horses
An image of a golden first place award from Geoguessr
'We're actually getting GeoGuessr on Steam before GTA 6': the Google Street View puzzler arrives on Valve's platform this April
Napster client circa 1999
Former music-pirating platform Napster to be reborn rather ironically as a metaverse for musicians to connect with their fans after $207 million deal
The snazzy red and black HyperX Cloud Alpha wireless headphones float in a teal void. The microphone is attached to the headset.
The best wireless gaming headset is now even better in the Amazon Big Spring Sale, boasting a more than $50 discount
A chip being held up in an Intel fab
Intel is reportedly 'working to finalize commitments from Nvidia' as a foundry partner, suggesting gaming potential for the 18A node