CVE-2025-23253CWE-547
NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying…
Low · published April 22, 2025
What it is
NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
The record
Technical detail
- CVSS v3.1
- 2.5 · LOW
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
- CVSS v4.0
- Not supplied
- EPSS
- 0.00161 · 5.6th percentile
- Weakness
- CWE-547 · Use of Hard-coded, Security-relevant Constants
- Published
- 2025-04-22T18:45Z
EPSS history
Timeline