CVE-2025-33231
Estado: AnalizadaMedia (6.7)—
NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service and information disclosure.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-427
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-33231",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-33231",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-21T04:55:30.428360Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@nvidia.com",
"affectedData": [
{
"vendor": "NVIDIA",
"product": "CUDA Toolkit",
"versions": [
{
"status": "affected",
"version": "All versions prior to CUDA Toolkit 13.1"
}
],
"platforms": [
"Windows",
"Linux"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-20T18:16:02.790",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33231",
"tags": [
"US Government Resource",
"VDB Entry"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5755",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2025-33231",
"tags": [
"Third Party Advisory"
],
"source": "psirt@nvidia.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service and information disclosure."
},
{
"lang": "es",
"value": "NVIDIA Nsight Systems para Windows contiene una vulnerabilidad en el mecanismo de carga de DLL de la aplicación donde un atacante podría causar un elemento de ruta de búsqueda incontrolado al explotar rutas de búsqueda de DLL inseguras. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, escalada de privilegios, manipulación de datos, denegación de servicio y revelación de información."
}
],
"lastModified": "2026-06-17T09:13:16.737",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D53794E-E526-471B-94F5-F9BCC26C1BC1",
"versionEndExcluding": "13.1.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@nvidia.com"
}