CVE-2025-33224

9.8

NVIDIA · Isaac Launchable

NVIDIA Isaac Launchable is susceptible to execution with unnecessary privileges, potentially allowing unauthenticated remote attackers to achieve code execution or data tampering.

Executive summary

A critical vulnerability in NVIDIA Isaac Launchable allows unauthenticated remote attackers to execute code with excessive privileges, posing a severe risk to system integrity.

Vulnerability

This issue is classified as CWE-250 (Execution with Unnecessary Privileges). The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that the vulnerability is remotely exploitable by an unauthenticated attacker without requiring user interaction.

Business impact

Successful exploitation grants an attacker significant control over the affected system, enabling full code execution, privilege escalation, and unauthorized data modification. Given the CVSS score of 9.8, this vulnerability represents a critical risk to business operations, potentially leading to total system compromise and data exfiltration.

Remediation

Immediate Action: Upgrade to NVIDIA Isaac Launchable version 1.1 or later immediately to resolve the privilege management flaw.

Proactive Monitoring: Monitor system and application logs for unusual process executions or unexpected administrative actions originating from network-accessible services.

Compensating Controls: Deploy Network Access Control (NAC) and restrict access to the application to trusted IP addresses until the patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability is critical and requires immediate attention due to its ease of exploitation and potential for total system impact. Organizations should prioritize patching NVIDIA Isaac Launchable to version 1.1 to eliminate the risk of remote code execution.

More NVIDIA CVEs