CVE-2025-23352
BaseFortify
Publication date: 2025-10-23
Last updated on: 2025-10-27
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | vgpu_software | * |
| nvidia | display_driver | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-824 | The product accesses or uses a pointer that has not been initialized. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
This vulnerability can have severe impacts including unauthorized code execution, denial of service, escalation of privileges, information disclosure, and data tampering. These impacts can compromise the confidentiality, integrity, and availability of affected systems. [1]
Can you explain this vulnerability to me?
CVE-2025-23352 is a vulnerability in NVIDIA's vGPU software, specifically in the Virtual GPU Manager. It involves an uninitialized pointer access that can be triggered by a malicious guest virtual machine. Exploiting this flaw could allow an attacker to execute code, cause denial of service, escalate privileges, disclose information, or tamper with data. [1]