Nvidia GeForce Now has a nasty security flaw — what to do now

Nvidia GeForce Now
(Image credit: Nvidia)

Windows users of Nvidia's GeForce Now cloud-gaming service need to update their desktop software, as there's a serious security flaw that could let malware take over the PC.

You've got to update the Windows GeForce Now client software to at least version 2.0.25.119, per an Nvidia security advisory. The Mac, Chrome OS, Android and Nvidia Shield GeForce Now clients are not affected.

"NVIDIA GeForce NOW application software on Windows contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges," states the advisory.

In plain English, according to Threatpost, this means that an attacker with access to the PC — perhaps a person, or perhaps a piece of malware that got installed by other means — would be able to plant a booby-trapped file that the GeForce Now program could load and run. That in turn could lead to further malware infection or attacker control of the machine.

You can update GeForce Now to version 2.0.25.119 by simply launching the application. The new version should automatically download itself, after which you need to follow the prompts to install it. If that doesn't work, Nvidia has a help page recommending various measures to take.

GeForce Now is a freemium subscription service that lets gamers play games on Nvidia's own servers, accessing the games remotely from client machines. It isn't the same as the GeForce Experience software that's used to manage Nvidia graphics-card settings and driver updates.

The games are bought from Steam or other digital distributors. You've got to pay $5 per month for game sessions lasting longer than an hour. 

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now