OS Command Injection Vulnerability in NVIDIA Nsight Systems for Linux
CVE-2025-33230
7.3HIGH
What is CVE-2025-33230?
NVIDIA Nsight Systems for Linux features a vulnerability within its .run installer that allows for OS command injection. By providing a malicious string during the installation process, an attacker can manipulate the system. Exploiting this vulnerability may grant the attacker elevated privileges, enabling unauthorized code execution, modification of data, service disruptions, and potential information leaks.
Affected Version(s)
CUDA Toolkit Windows All versions prior to CUDA Toolkit 13.1