CVE-2025-33220

7.8

NVIDIA · vGPU software

A use after free vulnerability in the NVIDIA Virtual GPU Manager allows a malicious guest to potentially achieve code execution or escalate privileges.

Executive summary

A high severity use after free vulnerability in NVIDIA vGPU software could allow a local guest user to execute arbitrary code or compromise system integrity.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Virtual GPU Manager. An attacker with local access as a guest user can trigger this flaw to achieve remote code execution, escalate privileges, tamper with data, or cause a denial of service.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high risk to organizational security. Successful exploitation allows a malicious actor to break out of the guest environment, potentially leading to full system compromise, exfiltration of sensitive data, or complete service disruption for virtualized workloads.

Remediation

Immediate Action: Update affected NVIDIA drivers to the versions specified in the vendor security advisory (a_id/5747) immediately.

Proactive Monitoring: Monitor virtualized environments for unexpected guest crashes or anomalous system calls originating from GPU-bound processes.

Compensating Controls: Ensure strict isolation policies for virtual machines and limit user access to guest environments where GPU passthrough is enabled.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for privilege escalation and code execution, administrators should prioritize updating all host systems running the affected NVIDIA vGPU drivers. Applying the vendor-provided patches is the only effective way to eliminate the underlying memory management defect and ensure the continued security of the virtualized infrastructure.

More NVIDIA CVEs

Sources