CVE-2025-33220
7.8NVIDIA · vGPU software
A use after free vulnerability in the NVIDIA Virtual GPU Manager allows a malicious guest to potentially achieve code execution or escalate privileges.
Executive summary
A high severity use after free vulnerability in NVIDIA vGPU software could allow a local guest user to execute arbitrary code or compromise system integrity.
Vulnerability
This is a use after free vulnerability (CWE-416) within the Virtual GPU Manager. An attacker with local access as a guest user can trigger this flaw to achieve remote code execution, escalate privileges, tamper with data, or cause a denial of service.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high risk to organizational security. Successful exploitation allows a malicious actor to break out of the guest environment, potentially leading to full system compromise, exfiltration of sensitive data, or complete service disruption for virtualized workloads.
Remediation
Immediate Action: Update affected NVIDIA drivers to the versions specified in the vendor security advisory (a_id/5747) immediately.
Proactive Monitoring: Monitor virtualized environments for unexpected guest crashes or anomalous system calls originating from GPU-bound processes.
Compensating Controls: Ensure strict isolation policies for virtual machines and limit user access to guest environments where GPU passthrough is enabled.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for privilege escalation and code execution, administrators should prioritize updating all host systems running the affected NVIDIA vGPU drivers. Applying the vendor-provided patches is the only effective way to eliminate the underlying memory management defect and ensure the continued security of the virtualized infrastructure.