CVE-2025-23345

MEDIUM

NVIDIA - Info Disclosure/DoS

Title source: llm
STIX 2.1

Description

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

Scores

CVSS v3 4.4
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (23)
NVIDIA/GeForce All driver versions prior to 535.274.02
NVIDIA/GeForce All driver versions prior to 570.195.03
NVIDIA/GeForce All driver versions prior to 580.95.05
NVIDIA/GeForce All driver versions prior to 581.42
NVIDIA/Guest driver 535.261.03(All versions prior to and including vGPU 16.11)
NVIDIA/Guest driver 539.41(All versions prior to and including vGPU 16.11)
NVIDIA/Guest driver 570.172.08(All versions prior to and including vGPU 18.4)
NVIDIA/Guest driver 573.48(All versions prior to and including vGPU 18.4)
NVIDIA/Guest driver 580.82.07(All versions prior to and including vGPU 19.1)
NVIDIA/Guest driver 580.82.07(All versions up to and including the August 2025 release)
... and 13 more
Published Oct 23, 2025
Tracked Since Feb 18, 2026