CVE-2025-33231 is a DLL hijacking vulnerability affecting NVIDIA Nsight Systems for Windows, as well as Microsoft and NVIDIA CUDA Toolkit on Windows. An attacker could exploit insecure DLL search paths to achieve code execution, privilege escalation, data tampering, denial of service, and information disclosure. Rated 6.7 MEDIUM, exploitation requires local access and user interaction, but has high impact across confidentiality, integrity, and availability. Currently, there is no public exploit code, Metasploit modules, or significant community discussion or media coverage, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.1.0CPE matchmatch criteria | cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.