NVIDIA has fixed a critical vulnerability in its Windows application that could allow local attackers to arbitrary code execute and escalate privileges on vulnerable systems.

Reported as CVE-2025-23358, this vulnerability exists in the installer component and poses a significant security risk to Windows users using the application. The vulnerability stems from a “search path element issue” within the NVIDIA App installer (CWE-427).
See also: Critical RCE Vulnerability in Anthropic's Claude Desktop
An attacker with local access and low privileges could exploit this vulnerability by manipulating the search path to inject malicious code. The vulnerability requires user interaction to be triggered, but successful exploitation allows full code execution and privilege escalation across the entire system. With a CVSS v3.1 baseline score of 8.2, the vulnerability is considered moderately severe.

As mentioned earlier, the attack is local in nature. The attacker must have physical or logical access to the target machine. However, the low complexity of the attack, combined with the possibility of privilege escalation, makes this vulnerability particularly dangerous in multi-user environments and corporate settings.
See also: Multiple vulnerabilities in Django allow SQL Injection and DoS
NVIDIA Windows application versions prior to 11.0.5.260 are vulnerable to this attack. The company recommends that all affected users immediately download and install version 11.0.5.260 or later from the official NVIDIA application website.
This vulnerability highlights the importance of keeping software up to date, even for add-on applications like NVIDIA's utility software. Attackers often target installation components because they are often run with elevated privileges during installation.
See also: AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

NVIDIA App for Windows Vulnerability
To protect your system, download the latest version of the NVIDIA application from the official application website. The patch addresses the issue immediately and eliminates the code execution channel. Organizations that manage a large number of NVIDIA-equipped workstations should prioritize the deployment of this update across their infrastructure. Security teams should verify their software inventory to identify systems running older versions of the NVIDIA application and coordinate rapid remediation efforts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
