CVE-2025-23253

CVSS 3.1 Score 2.5 of 10 (low)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 547

Summary

CVE-2025-23253 is a vulnerability affecting the NVIDIA NvContainer service for Windows. This issue arises due to a hard-coded constant in OpenSSL used by the service. An attacker can exploit this vulnerability by carefully placing a malicious DLL in a specific hard-coded path. Successful exploitation could result in various outcomes, including code execution, denial of service, privilege escalation, information disclosure, or data tampering. Users are advised to update the NvContainer service as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share