CVE-2025-23347

7.8

NVIDIA · GeForce, RTX, Quadro, NVS, Tesla

NVIDIA Project G-Assist contains a vulnerability involving incorrect default permissions that may allow a local attacker to escalate privileges and perform unauthorized actions.

Executive summary

A vulnerability in NVIDIA driver software could allow a local authenticated attacker to escalate privileges and achieve code execution on the host system.

Vulnerability

The flaw is categorized as an Incorrect Default Permissions issue (CWE-276) within the Project G-Assist component. It requires a local attacker with low privileges to trigger, potentially leading to arbitrary code execution, privilege escalation, or system disruption.

Business impact

The potential for privilege escalation and code execution poses a severe risk to system integrity and data confidentiality. With a CVSS score of 7.8, this vulnerability is classified as High, indicating that a successful compromise could allow an attacker to bypass security controls and gain administrative control over the affected workstation or server.

Remediation

Immediate Action: Update all affected NVIDIA driver installations to the latest patched version (581.42 or 573.76, depending on the specific product line) as directed by the official NVIDIA security bulletin.

Proactive Monitoring: Monitor system logs for unauthorized attempts to access restricted directories or unusual process execution patterns that may indicate a privilege escalation attempt.

Compensating Controls: Ensure that local user accounts are restricted to the minimum necessary permissions and implement endpoint detection and response tools to identify anomalous activity originating from driver-related processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the potential for complete system compromise, organizations should prioritize updating NVIDIA drivers across all relevant hardware platforms. Administrators must verify that the installed driver versions match the specific requirements outlined in the NVIDIA security advisory to ensure full protection against this privilege escalation vulnerability.

More NVIDIA CVEs

Sources