
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-33231 is a DLL search order hijacking vulnerability in NVIDIA Nsight Systems for Windows, classified under CWE-427 (Uncontrolled Search Path Element). The vulnerability exists in the application's DLL loading mechanism, where insecure DLL search paths can be exploited by a local attacker to load a malicious DLL. It affects NVIDIA CUDA Toolkit versions prior to 13.1.0 on Windows. The CVE was published on January 20, 2026, with NIST initial analysis completed on February 2, 2026. NVIDIA assigned a CVSS v3.1 base score of 6.7 (Medium) (NVIDIA Advisory).
The root cause is CWE-427 (Uncontrolled Search Path Element): NVIDIA Nsight Systems for Windows does not properly restrict the directories searched when loading DLLs, allowing an attacker to place a malicious DLL in a location that the application searches before the legitimate DLL path. Exploitation requires local access with low privileges and user interaction (e.g., a victim launching the application), making it a classic DLL search order hijacking scenario mapped to MITRE ATT&CK technique T1574.001 (DLL Search Order Hijacking). The attack complexity is rated High, as the attacker must position the malicious DLL in the correct search path location before the application is executed (NVIDIA Advisory, Feedly).
Successful exploitation can lead to arbitrary code execution in the context of the user running NVIDIA Nsight Systems, with potential for privilege escalation, data tampering, denial of service, and information disclosure. Because the vulnerability can result in code execution under the application's security context, an attacker could leverage it for lateral movement or persistence on the compromised Windows host. All three pillars of the CIA triad are rated High impact by NVIDIA (NVIDIA Advisory, SecurityOnline).
cmd.exe, powershell.exe, network tools) shortly after application launch.NVIDIA has released a patch in CUDA Toolkit version 13.1.0, which includes an updated Nsight Systems for Windows that resolves the insecure DLL search path issue. Users should update to CUDA Toolkit 13.1.0 or later as the primary remediation. As interim workarounds: restrict file system write permissions on directories in the DLL search path to prevent unprivileged users from placing malicious DLLs; implement application whitelisting (e.g., via Windows Defender Application Control) to control which DLLs can be loaded; and limit local system access to trusted users only (NVIDIA Advisory).
Security news outlets including SecurityOnline and GBHackers covered the vulnerability as part of broader reporting on NVIDIA CUDA Toolkit security flaws in January 2026, noting the potential for code execution and privilege escalation. Tenable added detection coverage via their plugin pipeline. Community reaction has been measured given the Medium CVSS score, local-only attack vector, and absence of public exploits (SecurityOnline, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."