« Volver al listado

CVE-2025-33220

Estado: AplazadaAlta (7.8)—

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE en vGPU Manager con acceso local (AV:L) sin interacción (UI:N) y CWE-416 (use-after-free) que permite escalada de privilegios, ejecución de código e información disclosure en el hipervisor.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-33220",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-33220",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-29T04:55:54.370394Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "GeForce",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 590.48.01"
            }
          ],
          "platforms": [
            "Linux(R590)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "GeForce",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 580.126.09"
            }
          ],
          "platforms": [
            "Linux(R580)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "GeForce",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 570.211.01"
            }
          ],
          "platforms": [
            "Linux(R570)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "GeForce",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 535.288.01"
            }
          ],
          "platforms": [
            "Linux(R535)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 590.48.01"
            }
          ],
          "platforms": [
            "Linux(R590)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 580.126.09"
            }
          ],
          "platforms": [
            "Linux(R580)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 570.211.01"
            }
          ],
          "platforms": [
            "Linux(R570)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "RTX PRO, RTX, Quadro",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 535.288.01"
            }
          ],
          "platforms": [
            "Linux(R535)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 590.48.01"
            }
          ],
          "platforms": [
            "Linux(R590)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 580.126.09"
            }
          ],
          "platforms": [
            "Linux(R580)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 570.211.01"
            }
          ],
          "platforms": [
            "Linux(R570)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Tesla",
          "versions": [
            {
              "status": "affected",
              "version": "All driver versions prior to 535.288.01"
            }
          ],
          "platforms": [
            "Linux(R535)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Virtual GPU Manager",
          "versions": [
            {
              "status": "affected",
              "version": "580.105.06(All versions prior to and including vGPU software 19.3)"
            }
          ],
          "platforms": [
            "XenServer",
            "VMware vSphere",
            "Red Hat Enterprise Linux KVM",
            "Ubuntu(vGPU 19)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Virtual GPU Manager",
          "versions": [
            {
              "status": "affected",
              "version": "570.195.02(All versions prior to and including vGPU software 18.5)"
            }
          ],
          "platforms": [
            "XenServer",
            "VMware vSphere",
            "Red Hat Enterprise Linux KVM",
            "Ubuntu(vGPU 18)"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NVIDIA",
          "product": "Virtual GPU Manager",
          "versions": [
            {
              "status": "affected",
              "version": "535.274.03(All versions prior to and including vGPU software 16.13)"
            }
          ],
          "platforms": [
            "XenServer",
            "VMware vSphere",
            "Red Hat Enterprise Linux KVM",
            "Ubuntu(vGPU 16)"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-28T18:16:48.857",
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33220",
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5747",
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33220",
      "source": "psirt@nvidia.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure."
    },
    {
      "lang": "es",
      "value": "El software NVIDIA vGPU contiene una vulnerabilidad en el Virtual GPU Manager, en el que un invitado malicioso podría lograr acceder a la memoria del montículo después de que la memoria ha sido liberada. Si la vulnerabilidad se explota con éxito se podría ejecutar código, escalar privilegios, manipular datos, realizar denegaciones de servicio o revelar información."
    }
  ],
  "lastModified": "2026-06-17T09:13:15.623",
  "sourceIdentifier": "psirt@nvidia.com"
}