CVE-2025-33231 Details
Description
NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service and information disclosure.
A vulnerability exists in NVIDIA Nsight Systems for Windows due to an insecure DLL loading mechanism. This flaw allows an attacker to manipulate the search path for DLLs, potentially leading to unauthorized code execution, privilege escalation, data tampering, denial of service, and information disclosure.
Users are advised to upgrade to the latest version of the NVIDIA CUDA Toolkit, available on the CUDA Toolkit Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2025-33231 | [email protected] | US Government ResourceVDB Entry |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5755 | [email protected] | PatchVendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-33231 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nvidia cuda toolkit | < 13.1.0 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | Initial Analysis | [email protected] |
| Jan 20, 2026 | New CVE Received | [email protected] |