Wiz Agents & Workflows are here

CVE-2025-23309
NVIDIA Graphics Driver vulnerability analysis and mitigation

Overview

NVIDIA Display Driver contains a vulnerability (CVE-2025-23309) where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation of privileges, code execution, and data tampering. The vulnerability was discovered by Daniel Rhea and disclosed on October 9, 2025 (NVIDIA Bulletin, NVD).

Technical details

The vulnerability is classified as CWE-427 (Uncontrolled Search Path Element) with a CVSS v3.1 base score of 8.2 (High severity). The attack vector is Local (AV:L) with Low attack complexity (AC:L), requiring Low privileges (PR:L) and User interaction (UI:R). The scope is Changed (S:C) with High impact on Confidentiality, Integrity, and Availability (C:H/I:H/A:H) (NVIDIA Bulletin).

Impact

A successful exploitation of this vulnerability could lead to multiple severe consequences including denial of service, escalation of privileges, code execution, and data tampering in affected systems (NVIDIA Bulletin).

Mitigation and workarounds

NVIDIA has released software security updates to address this vulnerability. For Windows systems, updates are available in driver branches R580, R570 (version 573.76), and R535 (version 539.56). Users are advised to download and install these updates through the NVIDIA Driver Downloads page. For systems using earlier branch releases, NVIDIA recommends upgrading to the latest branch release (NVIDIA Bulletin).

Additional resources


SourceThis report was generated using AI

Related NVIDIA Graphics Driver vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-23347HIGH7.8
  • NVIDIA Graphics DriverNVIDIA Graphics Driver
  • cpe:2.3:a:nvidia:gpu_driver
NoYesOct 23, 2025
CVE-2025-23330MEDIUM5.5
  • NVIDIA Graphics DriverNVIDIA Graphics Driver
  • nvidia-graphics-drivers
NoYesOct 23, 2025
CVE-2025-23300MEDIUM5.5
  • NVIDIA Graphics DriverNVIDIA Graphics Driver
  • nvidia-graphics-drivers
NoYesOct 23, 2025
CVE-2025-23332MEDIUM5
  • NVIDIA Graphics DriverNVIDIA Graphics Driver
  • cpe:2.3:a:nvidia:gpu_driver
NoYesOct 23, 2025
CVE-2025-23345MEDIUM4.4
  • NVIDIA Graphics DriverNVIDIA Graphics Driver
  • nvidia-graphics-drivers-legacy-390xx
NoYesOct 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management