CVE-2025-23245: Medium severity nvidia virtual gpu graphics driver vulnerability
Published May 1, 2025
·Updated
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service.
Affected Software
1 affected component
Nvidia vGPU software
Event History
May 1, 2025
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-23245?
CVE-2025-23245 is considered to have a high severity due to the potential for code execution and data tampering.
2
How do I fix CVE-2025-23245?
To fix CVE-2025-23245, update to the latest version of NVIDIA TensorRT-LLM as recommended by NVIDIA.
3
What systems are affected by CVE-2025-23245?
CVE-2025-23245 affects the NVIDIA TensorRT-LLM on any platform where it is deployed.
4
What types of attacks can CVE-2025-23245 facilitate?
CVE-2025-23245 can facilitate attacks that lead to code execution, information disclosure, and data tampering.
5
Who is vulnerable to CVE-2025-23245?
Any user with local access to the TRTLLM server could be vulnerable to the exploitation of CVE-2025-23245.