CVE-2025-23355
BaseFortify
Publication date: 2025-10-01
Last updated on: 2025-10-22
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | nsight_graphics | to 2025.3 (exc) |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the NVIDIA Nsight Graphics for Windows, specifically in an ngfx component. It allows an attacker to perform a DLL hijacking attack, which means the attacker can trick the software into loading a malicious DLL file. Exploiting this vulnerability could enable the attacker to execute arbitrary code, escalate their privileges, tamper with data, or cause a denial of service.
How can this vulnerability impact me? :
If exploited, this vulnerability can lead to serious impacts including unauthorized code execution on your system, escalation of privileges allowing the attacker to gain higher access rights, tampering with your data, and causing denial of service which can disrupt normal operations.