CVE-2025-33234

7.8

NVIDIA · runx

NVIDIA runx is vulnerable to OS command injection, which may allow a local attacker to execute arbitrary code, escalate privileges, or cause a denial of service.

Executive summary

A critical OS command injection vulnerability in NVIDIA runx allows local attackers to achieve full system compromise, including code execution and data tampering.

Vulnerability

This is an OS command injection vulnerability (CWE-78) occurring in NVIDIA runx. An attacker with local access and low privileges (PR:L) can inject malicious commands that execute with the privileges of the application.

Business impact

The potential for unauthorized code execution, privilege escalation, and full system impact poses a severe risk to organizational assets. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as it facilitates complete control over the affected system, potentially leading to data exfiltration or total service disruption.

Remediation

Immediate Action: Review the official NVIDIA security advisory (a_id/5764) and apply the latest security patches or configuration changes provided by the vendor immediately.

Proactive Monitoring: Monitor system logs for suspicious process execution patterns or unexpected command-line arguments that deviate from standard operational behavior.

Compensating Controls: Implement strict local access controls and ensure the principle of least privilege is applied to all users who have access to systems running NVIDIA runx.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability represents a significant security risk due to the potential for OS command injection. IT administrators must prioritize this issue by applying the latest vendor-supplied updates or security mitigations as soon as they become available. Failure to address this flaw could allow local attackers to compromise the integrity and availability of the host system.

More NVIDIA CVEs

Sources