Multiple NVIDIA Flaws Allow Attackers to Escalate Privileges on Systems
NVIDIA has released a critical security update addressing multiple vulnerabilities in its NVIDIA App software, which could allow attackers to escalate privileges on Windows systems.
NVIDIA has released a critical security update addressing multiple vulnerabilities in its NVIDIA App software, which could allow attackers to escalate privileges on Windows systems.
The vulnerabilities, resolved in the September 2025 update, are due to improper file handling during the installation of Frameview SDK components.
Users of NVIDIA App on Windows 10 and 11 are advised to install version 11.0.5.245 or later to secure their systems.
The primary vulnerability, identified as CVE-2025-23297, exists in the NVIDIA Installer for NvAPP on Windows.
During the Frameview SDK installation process, an unprivileged local user could modify files within the Frameview SDK directory.
Exploitation of this vulnerability could enable an attacker to gain elevated privileges, potentially leading to full system compromise.
Local unprivileged access is required to execute the exploit. No user interaction is needed once local access is obtained. A successful attack can compromise system confidentiality, integrity, and availability. The vulnerability was reported by Dong-uk Kim and JunYoung Park of KAIST Hacking Lab.
The vulnerabilities, resolved in the September 2025 update, are due to improper file handling during the installation of Frameview SDK components.
CVE ID Base Score Severity Impact
CVE-2025-23297 7.8 High Escalation of privileges
This security update is applicable to NVIDIA App running on Windows:
CVE IDs Addressed Product Platform / OS Affected Versions Updated Version
CVE-2025-23297 NVIDIA App Windows 10 / 11 All versions prior to 11.0.5.245 11.0.5.245
To protect systems from these vulnerabilities:
Download and install the latest NVIDIA App update (version 11.0.5.245) from the NVIDIA App site. Verify installation success by launching NVIDIA App and checking the version in the “About” section. Subscribe to NVIDIA Product Security bulletins for notifications of future updates. Report any anomalies via the NVIDIA Product Security page to assist in a rapid response.
NVIDIA acknowledges the contribution of Dong-uk Kim and JunYoung Park of KAIST Hacking Lab for responsibly disclosing CVE-2025-23297.
All NVIDIA materials are provided “as is” without warranties. Specifications are subject to change without notice.
NVIDIA is not liable for third-party patent infringements or system misconfigurations resulting from the use of this information.
Based on reporting by GBHackers.
