Security researchers recently uncovered a critical vulnerability in the NVIDIA Omniverse Launcher that could allow attackers to exploit CORS vulnerability on the affected versions of the NVIDIA Omniverse Launcher application, leading to privilege escalation and remote access code execution on NVIDIA Omniverse Launcher. The flaw tracked as CVE‑2022‑21817 has a base score of 9.3 in CVSS v3.1. We have created this post to make all NVIDIA Omniverse Launcher users aware of the flaw. In this post, let’s see how to Fix CVE‑2022‑21817- A CORS vulnerability in NVIDIA Omniverse Launcher.
This video is published by
Omniverse Launcher is an open platform created by NVIDIA for those artistic companies who develop creative virtual assets. This innovative platform is used majorly to build virtual collaboration on creative assets delivered with real-time, physically accurate simulation. It gives opportunities to create the entire VR ecosystem.
Cross-Origin Resource Sharing (CORS) vulnerability in NVIDIA Omniverse Launcher allows an unprivileged remote attacker to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.
Associated CVE ID | CVE‑2022‑21817 |
Description | A CORS vulnerability in NVIDIA Omniverse Launcher App |
Associated ZDI ID | – |
CVSS Score | 9.3 Critical |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Impact Score | 5.8 |
Exploitability Score | 2.8 |
Attack Vector (AV) | Network |
Attack Complexity (AC) | Low |
Privilege Required (PR) | None |
User Interaction (UI) | Required |
Scope | Changed |
Confidentiality (C) | High |
Integrity (I) | High |
availability (a) | High |
How To Fix CVE‑2022‑21817- A CORS Vulnerability In NVIDIA Omniverse Launcher App?
All the versions prior to 1.5.2 are affected by CVE‑2022‑21817 vulnerability. The flaw has been fixed in v1.5.2 and made available for download. We recommend upgrading to the latest available version.
For any queries, please contact NVIDIA Support.
We hope this post would help you know about How to Fix CVE‑2022‑21817- A CORS vulnerability in NVIDIA Omniverse Launcher App. Thanks for reading this threat post. Please share this post and help to secure the digital world. Visit our social media page in Facebook, LinkedIn, Twitter, Telegram, Tumblr, & Medium and subscribe to receive updates like this.
You may also like these articles:
How to Fix CVE-2022-28199- Vulnerability in NVIDIA Data Plane Development Kit
How To Fix CVE-2022-0540- A Critical Authentication Bypass Vulnerability In Jira Seraph
How To Fix CVE-2022-24348- A Path Traversal Vulnerability In Argo CD
How To Fix CVE-2022-0778- A Denial-Of-Service Vulnerability In OpenSSL
How To Fix CVE-2022-26809- A Critical RCE Vulnerability In Windows RPC Runtime
Arun KL is a cybersecurity professional with 15+ years of experience in IT infrastructure, cloud security, vulnerability management, Penetration Testing, security operations, and incident response. He is adept at designing and implementing robust security solutions to safeguard systems and data. Arun holds multiple industry certifications including CCNA, CCNA Security, RHCE, CEH, and AWS Security.
“Knowledge Arsenal: Empowering Your Security Journey through Continuous Learning”
"Cybersecurity All-in-One For Dummies" offers a comprehensive guide to securing personal and business digital assets from cyber threats, with actionable insights from industry experts.
BurpGPT is a cutting-edge Burp Suite extension that harnesses the power of OpenAI's language models to revolutionize web application security testing. With customizable prompts and advanced AI capabilities, BurpGPT enables security professionals to uncover bespoke vulnerabilities, streamline assessments, and stay ahead of evolving threats.
PentestGPT, developed by Gelei Deng and team, revolutionizes penetration testing by harnessing AI power. Leveraging OpenAI's GPT-4, it automates and streamlines the process, making it efficient and accessible. With advanced features and interactive guidance, PentestGPT empowers testers to identify vulnerabilities effectively, representing a significant leap in cybersecurity.
Tenable BurpGPT is a powerful Burp Suite extension that leverages OpenAI's advanced language models to analyze HTTP traffic and identify potential security risks. By automating vulnerability detection and providing AI-generated insights, BurpGPT dramatically reduces manual testing efforts for security researchers, developers, and pentesters.
Microsoft Security Copilot is a revolutionary AI-powered security solution that empowers cybersecurity professionals to identify and address potential breaches effectively. By harnessing advanced technologies like OpenAI's GPT-4 and Microsoft's extensive threat intelligence, Security Copilot streamlines threat detection and response, enabling defenders to operate at machine speed and scale.