solution Contentsolution Content

SUPPORT COMMUNICATION- SECURITY BULLETIN

Document ID: c06993751

Version: 6

HPSBHF03710 rev. 6 - NVIDIA GPU Display Driver January 2021 Security Updates

Notice: The information in this security bulletin should be acted upon as soon as possible.

Release date : 07-Jan-2021

Last updated : 24-Jun-2021

Potential Security Impact:
Escalation of Privilege, Denial of Service, and Information Disclosure
Source: HP, HP Product Security Response Team (PSRT)
Reported By: NVIDIA

VULNERABILITY SUMMARY
NVIDIA has informed HP of potential security vulnerabilities in the NVIDIA GPU Display Driver and Software which may lead to escalation of privileges, denial of service, and information disclosure.
For detailed information on the vulnerabilities visit the NVIDIA Product Security page at https://www.nvidia.com/security (in English).
Reference Number
NVIDIA Security Bulletin 5142 - NVIDIA GPU Display Driver January 2021: CVE-2021-1051, CVE-2021-1052, CVE-2021-1053, CVE-2021-1054, CVE-2021-1055; PSR-2021-0005
HP does not distribute NVIDIA vGPU Software and is not impacted by CVE-2021-1057, CVE-2021-1058, CVE-2021-1059, CVE-2021-1060, CVE-2021-1061, CVE-2021-1062, CVE-2021-1063, CVE-2021-1064, CVE-2021-1065, CVE-2021-1066.
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
See RESOLUTION section for impacted products.
BACKGROUND
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com
CVSS 3.1 Base Metrics
Reference
Base Vector
Base Score
CVE-2021-1051
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
8.4
CVE-2021-1052
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CVE-2021-1053
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
6.6
CVE-2021-1054
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
6.5
CVE-2021-1055
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
5.3
RESOLUTION
NVIDIA has released updates to mitigate the potential vulnerabilities. HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the potential vulnerability. See the affected platforms listed below.
Newer versions may become available and the minimum versions listed below may become obsolete. If a SoftPaq Link becomes invalid, check the HP Customer Support - Software and Driver Downloads site to obtain the latest update for your product model.
HP recommends keeping your system up to date with the latest firmware and software.
note:
This bulletin may be updated when new information and/or SoftPaqs are available.  Sign up for HP Subscriptions to be notified and receive:  
  • Product support eAlerts
  • Driver updates
  • Security Bulletin updates

Verify your display adapter and identify the driver version

Use Windows Device Manager to see if you have an impacted display adapter.
  1. Search Windows for Device Manager, and then click Device Manager in the list of results.
  2. Double-click Display Adapters.
  3. Double-click the NVIDIA product.
  4. Click the Driver tab.
  5. Check the driver version. If you have an earlier driver version than what is listed for your product, update the driver using the link provided in this document.
    note:
    The driver version can be identified by the last digits of the version number. For example, 26.21.14.4423 is 444.23.
Pending: SoftPaq is in progress.
Under investigation: System under investigation for impact, or SoftPaq under investigation for feasibility/availability.
Not available: SoftPaq not available due to technical or logistical constraints.
Check support page: The listed SoftPaq has been removed from downloaded site. SoftPaqs with newer versions may be available on the HP Customer Support - Software and Driver Downloads site.

Home PCs

note:
NVIDIA GPU Display Driver and vGPU software updates for HP home notebook and desktop PCs are available via Windows Update. Individual HP driver SoftPaqs will not be provided. For information about downloading software and driver updates through Windows update, go to HP PCs - Updating Drivers and Software with Windows Update (Windows 10, 8, 7).

Business Notebook PCs

Product Name
Component Type
Minimum Version
SoftPaq#
SoftPaq Link
Last Update
HP EliteBook 1050 G1
Windows 10
27.21.14.5269
SP111773
Rev 5
HP EliteBook 850 G7
Windows 10
27.21.14.5269
SP111619
Rev 3
HP ProBook 440 G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ProBook 440 G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ProBook 440 G6
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ProBook 440 G7
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ProBook 440 G8
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ProBook 450 G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ProBook 450 G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ProBook 450 G6
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ProBook 450 G7
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ProBook 450 G8
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ProBook 470 G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ProBook 470 G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ProBook 640 G8
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ProBook 650 G8
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ProBook x360 440 G1
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 15 G3
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 15 G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 15 G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 15 G6
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ZBook 17 G3
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 17 G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 17 G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook 17 G6
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ZBook Create G7
Windows 10
27.21.14.5269
SP111619
Rev 3
HP ZBook Firefly 14 G7
Windows 10
27.21.14.5269
SP111619
Rev 3
HP ZBook Firefly 14 inch G8 Mobile Workstation
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ZBook Firefly 15 G7
Windows 10
27.21.14.5269
SP111619
Rev 3
HP ZBook Firefly 15.6 inch G8 Mobile Workstation
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ZBook Fury 15 G7
Windows 10
27.21.14.5269
SP111619
Rev 3
HP ZBook Fury 17 G7
Windows 10
27.21.14.5269
SP111619
Rev 3
HP ZBook Power G7
Windows 10
27.21.14.5269
SP111850
Rev 3
HP ZBook Studio G3
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook Studio G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook Studio G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook Studio G7
Windows 10
27.21.14.5269
SP111619
Rev 5
HP ZBook Studio x360 G5
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZBook x2 G4
Windows 10
27.21.14.5269
SP111773
Rev 5
HP ZHAN 66 Pro 14 G2
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ZHAN 66 Pro 14 G3
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ZHAN 66 Pro 14 G4
Windows 10
27.21.14.5269
SP111850
Rev 5
HP ZHAN 66 Pro 15 G2
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ZHAN 66 Pro 15 G3
Windows 10
27.21.14.5269
SP111619
Check support page for newer driver
Rev 6
HP ZHAN 66 Pro G1
Windows 10
27.21.14.5269
SP111773
Rev 5

Business Desktop PCs

Product Name
Component Type
Minimum Version
SoftPaq #
SoftPaq Link
Last Update
HP EliteDesk 705 G2 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 705 G2 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 705 G2 Small Form Factor PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 705 G2 Small Form Factor PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 705 G3 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 705 G3 Microtower PC
Windows 7 64
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 705 G3 Small Form Factor PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 705 G3 Small Form Factor PC
Windows 7 64
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 705 G4 Microtower PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP EliteDesk 705 G4 Small Form Factor PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP EliteDesk 705 G4 Workstation Edition
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP EliteDesk 705 G5 Small Form Factor PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 800 G2 Small Form Factor PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 800 G2 Small Form Factor PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 800 G2 Tower PC
Windows 10
Not available
N/A
Not available
Rev 6
HP EliteDesk 800 G2 Tower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 800 G3 Small Form Factor PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 800 G3 Small Form Factor PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 800 G3 Tower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 800 G3 Tower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 800 G4 Small Form Factor PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 800 G4 Tower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 800 G4 Workstation Edition
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 800 G5 Small Form Factor PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 800 G5 Tower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 800 G6 Desktop Mini PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 800 G6 Small Form Factor PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 800 G6 Tower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 880 G2 Tower PC
Windows 10
Not available
N/A
Not available
Rev 6
HP EliteDesk 880 G2 Tower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 880 G3 Tower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 880 G3 Tower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP EliteDesk 880 G4 Tower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP EliteDesk 880 G5 Tower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteDesk 880 G6 Tower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteOne 800 G6 24 All-in-One PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP EliteOne 800 G6 27 All-in-One PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 400 G4 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 400 G4 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 400 G4 Small Form Factor PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP ProDesk 400 G4 Small Form Factor PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 400 G5 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 400 G5 Small Form Factor PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP ProDesk 400 G6 Microtower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 400 G6 Small Form Factor PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 405 G4 Small Form Factor PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP ProDesk 480 G4 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 480 G4 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 480 G5 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 480 G6 Microtower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 600 G2 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 600 G2 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 600 G2 Small Form Factor PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 600 G2 Small Form Factor PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 600 G3 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 600 G3 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 600 G3 Small Form Factor PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP ProDesk 600 G3 Small Form Factor PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 600 G4 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 600 G4 Small Form Factor PC
Windows 10
27.21.14.5785
SP112650
Check support page for newer driver
Rev 6
HP ProDesk 600 G5 Microtower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 600 G5 Microtower PC (with PCI slot)
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 600 G5 Small Form Factor PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 600 G6 Microtower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 600 G6 PCI Microtower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 680 G2 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 680 G2 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 680 G3 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 680 G3 Microtower PC
Windows 7/Windows 8.1
27.21.14.5749
SP111856
Rev 3
HP ProDesk 680 G4 Microtower PC
Windows 10
27.21.14.5749
SP111852
Rev 3
HP ProDesk 680 G4 Microtower PC (With PCI slot)
Windows 10
27.21.14.5749
SP111853
Rev 3
HP ProDesk 680 G6 PCI Microtower PC
Windows 10
27.21.14.5749
SP111853
Rev 3
HP Z1 Entry Tower G5
Windows 10
27.21.14.5749
SP111853
Rev 3
HP Z1 Entry Tower G6
Windows 10
27.21.14.5749
SP111853
Rev 3

Desktop Workstation PCs

Product Name
Operating System
Updated Version
SoftPaq #
SoftPaq Link
HP ZCentral 4R Workstation
Windows 10 - Quadro series
461.09
SP112186
HP Z VR Backpack Workstation G1
Windows 10
27.21.14.6093 Rev.A
SP112573
HP Z1 All-in-One G3 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z1 Entry Tower G5 Workstation
Windows 10 - Quadro series
461.09
SP112186
HP Z1 Entry Tower G6 Workstation
Windows 10 - Quadro series
461.09
SP112186
HP Z2 Mini G3 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z2 Mini G4 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z2 Mini G5 Workstation
Windows 10 - Quadro series
461.09
SP112186
HP Z2 Small Form Factor G4 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z2 Small Form Factor G5 Workstation
Windows 10 - Quadro series
461.09
SP112186
HP Z2 Tower G4 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z2 Tower G5 Workstation
Windows 10 - Quadro series
461.09
SP112186
HP Z238 Microtower Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z240 Small Form Factor Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z240 Small Form Factor Workstation
Windows 10 - NVS series
392.63
SP112647
HP Z240 Tower Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z240 Tower Workstation
Windows 10 - NVS series
392.63
SP112647
HP Z4 G4 Workstation (Core-X)
Windows 10 - Quadro series
461.09
SP112185
HP Z4 G4 Workstation (Xeon W)
Windows 10 - Quadro series
461.09
SP112185
HP Z440 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z440 Workstation
Windows 10 - NVS series
392.63
SP112647
HP Z6 G4 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z640 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z640 Workstation
Windows 10 - NVS series
392.63
SP112647
HP Z8 G4 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z840 Workstation
Windows 10 - Quadro series
461.09
SP112185
HP Z840 Workstation
Windows 10 - NVS series
392.63
SP112647

Retail Point-of-Sale systems

Product Name
Operating System
Minimum Version
SoftPaq #
SoftPaq Link
HP Engage Flex Pro Retail System
Windows 10
461.09
SP112186
HP Engage Flex Pro Retail System
Windows 10 IoT RS5/Windows 10 IoT RS1
461.09
SP112185
HP Engage Flex Pro-C Retail System
Windows 10
461.09
SP112186
HP Engage Flex Pro-C Retail System
Windows 10 IoT RS5/Windows 10 IoT RS1
461.09
SP112185

Immersive PCs

Product Name
Minimum Version
SoftPaq #
SoftPaq Link
Sprout Pro by HP G2
27.21.14.6111 Rev. Y
SP112505
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, visit https://www.hp.com/go/contacthp to learn about your HP support options.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp-security-alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via email, visit https://www.hp.com/go/alerts.
Security Bulletin Archive: To view released Security Bulletins, search the HP Support Site for "security bulletin".
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
GN
HP General Software
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version: 1 – 07 January 2021 Initial release. Version: 2 – 29 January 2021 Added table for Workstations. Version: 3 – 19 February 2021 Added tables for Business Notebook PCs, Business Desktop PCs, Retail Point-Of-Sales Systems, and Immersive PCs. Version: 4 – 27 February 2021 Completed updates to Workstations softpaq information. Version: 5 – 18 March 2021 Updated version and SoftPaq information for Business products, and added “Last Update” column to the Business Notebook and Desktop tables. Version: 6 – 24 June 2021 Final update for this bulletin, updated remaining “pending” links to “check support page” for latest version in the Business Notebook and Desktop tables.

HP Inc. shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. HP Inc. and the names of HP products referenced herein are trademarks of HP Inc. in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.