CVE-2025-23253
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
El servicio NVIDIA NvContainer para Windows contiene una vulnerabilidad en el uso de OpenSSL. Un atacante podría explotar un problema constante codificado copiando una DLL maliciosa en una ruta codificada. Una explotación exitosa de esta vulnerabilidad podría provocar ejecución de código, denegación de servicio, escalada de privilegios, divulgación de información o manipulación de datos.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-01-14 CVE Reserved
- 2025-04-22 CVE Published
- 2025-04-23 CVE Updated
- 2025-05-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-547: Use of Hard-coded, Security-relevant Constants
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5644 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
NVIDIA Search vendor "NVIDIA" | NVIDIA App Search vendor "NVIDIA" for product "NVIDIA App" | 11.0.2.337 Search vendor "NVIDIA" for product "NVIDIA App" and version "11.0.2.337" | en |
Affected
|