CVE-2025-33223

9.8

NVIDIA · Isaac Launchable

A vulnerability in NVIDIA Isaac Launchable permits unauthenticated remote attackers to execute operations with excessive privileges, leading to potential code execution or denial of service.

Executive summary

NVIDIA Isaac Launchable contains a critical privilege execution flaw that enables unauthenticated attackers to compromise the system remotely.

Vulnerability

This vulnerability involves CWE-250 (Execution with Unnecessary Privileges), allowing an unauthenticated attacker to abuse the application's process privileges. The CVSS vector indicates that no user interaction or authentication is required for a successful remote attack.

Business impact

The ability for an unauthenticated user to execute commands with elevated privileges poses a catastrophic risk to the confidentiality, integrity, and availability of the host system. With a CVSS score of 9.8, this flaw could be leveraged to disrupt services or steal sensitive data, necessitating urgent remediation.

Remediation

Immediate Action: Upgrade all instances of NVIDIA Isaac Launchable to version 1.1 or later to remediate the privilege execution vulnerability.

Proactive Monitoring: Review security logs for anomalous network traffic or unauthorized service calls that deviate from standard operational baselines.

Compensating Controls: Utilize a Web Application Firewall (WAF) or equivalent network filtering to block unauthorized access to the affected service until the update is deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity and the potential for complete system compromise, organizations must treat this update as high priority. Apply the vendor-provided patch to version 1.1 to ensure the environment is protected against unauthorized privilege escalation.

More NVIDIA CVEs