OpenSSL Vulnerability in NVIDIA NvContainer Service on Windows
CVE-2025-23253
2.5LOW
Summary
The NVIDIA NvContainer service for Windows is susceptible to a vulnerability stemming from improper handling of OpenSSL, where a hard-coded constant can be exploited. An attacker could craft a malicious DLL and place it in a predetermined path, potentially leading to various impacts such as code execution, denial of service, privilege escalation, information disclosure, or data tampering. It is imperative for users to assess their systems and apply recommended security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
NVIDIA App Windows All versions up to and including 11.0.2.337 (prod2 hotfix)
References
CVSS V3.1
Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved