CVE-2025-33217
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.20%
- Percentile among all scored CVEs: 9
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Primary impact
T1059Command and Scripting Interpreterexecution80 % - Secondary impact
T1005Data from Local Systemcollection70 % - Secondary impact
T1548Abuse Elevation Control Mechanismprivilege escalation75 %
AV:L sin UI requiere acceso local → T1068. Use-after-free (CWE-416) permite ejecución de código (T1059), escalada de privilegios (T1548) e información disclosure (T1005) según descripción oficial.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-416
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-33217",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-33217",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-29T04:55:51.034053Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@nvidia.com",
"affectedData": [
{
"vendor": "NVIDIA",
"product": "GeForce",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 591.59"
}
],
"platforms": [
"Windows(R590)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "RTX PRO, RTX, Quadro",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 591.59"
}
],
"platforms": [
"Windows(R590)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "RTX PRO, RTX, Quadro",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 582.16"
}
],
"platforms": [
"Windows(R580)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "RTX PRO, RTX, Quadro",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 573.96"
}
],
"platforms": [
"Windows(R570)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "RTX PRO, RTX, Quadro",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 539.64"
}
],
"platforms": [
"Windows(R535)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "Tesla",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 591.59"
}
],
"platforms": [
"Windows(R590)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "Tesla",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 582.16"
}
],
"platforms": [
"Windows(R580)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "Tesla",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 573.96"
}
],
"platforms": [
"Windows(R570)"
],
"defaultStatus": "unaffected"
},
{
"vendor": "NVIDIA",
"product": "Tesla",
"versions": [
{
"status": "affected",
"version": "All driver versions prior to 539.64"
}
],
"platforms": [
"Windows(R535)"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-28T18:16:48.377",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33217",
"source": "psirt@nvidia.com"
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5747",
"source": "psirt@nvidia.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2025-33217",
"source": "psirt@nvidia.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure."
},
{
"lang": "es",
"value": "El controlador de pantalla NVIDIA para Windows contiene una vulnerabilidad por la que un atacante podría desencadenar un 'use after free'. Si se explota con éxito se podría lograr la ejecución de código, la escalada de privilegios, la manipulación de datos, la denegación de servicio y la revelación de información."
}
],
"lastModified": "2026-06-17T09:13:15.283",
"sourceIdentifier": "psirt@nvidia.com"
}