CVE-2025-23253CWE-547

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying…

Low · published April 22, 2025

CVSS v3.1
2.5
EPSS
0%
Percentile
5.6
In the wild
Unconfirmed
What it is

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

The record
Technical detail
CVSS v3.1
2.5 · LOW
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00161 · 5.6th percentile
Weakness
CWE-547 · Use of Hard-coded, Security-relevant Constants
Published
2025-04-22T18:45Z
EPSS history
Timeline
  • 22 APR 18:45Z
    NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying…
    cvelistv5