logo

NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution

ID: f04c18e6-7ccd-5ecd-919f-b2b44c78c64c

STIX ID: report--f04c18e6-7ccd-5ecd-919f-b2b44c78c64c

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Varshini

...
...

NVIDIA patched four CUDA Toolkit flaws (CVE-2025-33228–33231) in Nsight Systems and related tools that enable local OS command injection, DLL load hijacking, and arbitrary code execution with high-impact consequences (privilege escalation, data tampering, DoS, and information disclosure). Affected versions are all releases prior to CUDA Toolkit 13.1 on Windows and Linux; NVIDIA recommends immediate upgrade to 13.1 and monitoring for anomalous Nsight script invocations or DLL loads, while noting no public PoCs or IoCs have been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.