« Back to list

CVE-2025-33217

Status: DeferredHigh (7.8)—

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L sin UI requiere acceso local → T1068. Use-after-free (CWE-416) permite ejecución de código (T1059), escalada de privilegios (T1548) e información disclosure (T1005) según descripción oficial.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-33217",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-33217",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-29T04:55:51.034053Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "GeForce",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 591.59"
            }
          ],
          "platforms": [
            "Windows(R590)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 591.59"
            }
          ],
          "platforms": [
            "Windows(R590)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 582.16"
            }
          ],
          "platforms": [
            "Windows(R580)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 573.96"
            }
          ],
          "platforms": [
            "Windows(R570)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 539.64"
            }
          ],
          "platforms": [
            "Windows(R535)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 591.59"
            }
          ],
          "platforms": [
            "Windows(R590)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 582.16"
            }
          ],
          "platforms": [
            "Windows(R580)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 573.96"
            }
          ],
          "platforms": [
            "Windows(R570)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 539.64"
            }
          ],
          "platforms": [
            "Windows(R535)"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-28T18:16:48.377",
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33217",
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5747",
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33217",
      "source": "psirt@nvidia.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure."
    },
    {
      "lang": "es",
      "value": "El controlador de pantalla NVIDIA para Windows contiene una vulnerabilidad por la que un atacante podría desencadenar un 'use after free'. Si se explota con éxito se podría lograr la ejecución de código, la escalada de privilegios, la manipulación de datos, la denegación de servicio y la revelación de información."
    }
  ],
  "lastModified": "2026-06-17T09:13:15.283",
  "sourceIdentifier": "psirt@nvidia.com"
}