CVE-2025-33229
7.3NVIDIA · Nsight Visual Studio
NVIDIA Nsight Visual Studio for Windows contains an uncontrolled search path element vulnerability in Nsight Monitor, which may allow local attackers to execute arbitrary code with elevated privileges.
Executive summary
A vulnerability in NVIDIA Nsight Monitor allows local attackers to achieve arbitrary code execution by exploiting an uncontrolled search path element.
Vulnerability
The flaw is an uncontrolled search path element (CWE-427) within the Nsight Monitor application. An attacker with local access (low privileges) can leverage this vulnerability to execute arbitrary code with the same privileges as the Nsight Monitor process.
Business impact
The exploitation of this vulnerability could lead to a complete compromise of the local environment where the affected software is installed. Given the CVSS score of 7.3, this represents a high-severity risk that could facilitate unauthorized data access, system-wide privilege escalation, or service disruption, which may negatively impact organizational security posture and data integrity.
Remediation
Immediate Action: Update NVIDIA CUDA Toolkit to version 13.1 or later to resolve the underlying search path vulnerability.
Proactive Monitoring: Monitor system logs for unexpected child process execution or unauthorized modifications to application directories and environment variables.
Compensating Controls: Restrict local user access to the installation directories of the Nsight Monitor application and ensure that standard user accounts lack permissions to modify system-wide PATH configurations.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing NVIDIA Nsight Visual Studio for development should prioritize upgrading to CUDA Toolkit 13.1 immediately. Given the potential for arbitrary code execution and privilege escalation, timely patching is essential to prevent local malicious actors from gaining control over development workstations.