Insecure DLL loading in CUDA Toolkit - CVE-2025-33229

 

Insecure DLL loading in CUDA Toolkit - CVE-2025-33229

Published: May 18, 2026


Vulnerability identifier: #VU131727
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-33229
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to uncontrolled search path element in Nsight Monitor when loading DLLs. A local user can place or cause the application to load a malicious DLL to execute arbitrary code.

Arbitrary code execution occurs with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application.


Affected software

CUDA Toolkit

How to mitigate CVE-2025-33229

Install security update from vendor's website.

CUDA Toolkit - update to 13.1.0

External References

Related Security Bulletins