CVE-2025-0467
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 823
Summary
CVE-2025-0467 is a vulnerability affecting kernel software running inside Guest Virtual Machines (VMs). It allows an attacker to exploit memory shared with the GPU Firmware, enabling them to write data outside the Guest's virtualised GPU memory. This could potentially lead to privilege escalation or data leakage. The impacted kernel software must be installed and running within the Guest VM for the vulnerability to be exploited. This issue poses a significant risk, especially in environments where virtualised GPUs are used extensively.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Graphics DDK