Installer Vulnerability in NVIDIA NVApp for Windows
CVE-2025-23358

8.2HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
4 November 2025

What is CVE-2025-23358?

The NVIDIA NVApp for Windows is vulnerable due to an issue in the installer that allows local attackers to manipulate the search path element. This vulnerability could be leveraged for unauthorized code execution and to escalate privileges within the system. Proper security measures and updates are essential to mitigate such risks.

Affected Version(s)

NVApp Windows All versions prior to 11.0.5.260

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.