NVIDIA Nsight Graphics (ngfx component, Windows): An ngfx component resolves a DLL from an untrusted search path, so
Impact
An ngfx component resolves a DLL from an untrusted search path, so an attacker who can drop a file in the right directory gets their code loaded the next time a developer launches Nsight Graphics. The consequence is code execution and privilege escalation on the machine of someone who profiles GPU workloads - exactly the account that tends to hold source access, signing material and cluster credentials. Low fleet-wide reach, high value per host.
Who can reach it
A local, low-privileged account that can write into a directory in the loader's search path, plus a real user actually starting Nsight Graphics. NVIDIA rates the complexity high, so this is targeted rather than opportunistic - but the required write is often available on shared dev boxes with a loose system PATH.
What to do
Upgrade Nsight Graphics to 2025.3 or later. Independently, sweep the system PATH on developer machines for entries that non-admin users can write to and remove them - that removes this whole class of hijack, not just this instance.
References
Related entries
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A second out-of-bounds write in SROOT firmwareCVE-2025-33190 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareMedium
- CUDA Toolkit: Code exec via path manipulation on library loadCVE-2025-33231 · CUDA ToolkitMedium
- NVIDIA GPU driver: out-of-bounds writes in the kernel mode layer reachable by a privileged local userCVE-2026-47509 · NVIDIA GPU Display Driver kernel mode layer (out-of-bounds writes)Medium
- NVIDIA GPU driver: unbounded string operation in the kernel mode layer causes an out-of-bounds readCVE-2026-47515 · NVIDIA GPU Display Driver kernel mode layer (unbounded string operation)Medium
- NVIDIA GPU driver: improper input validation in the kernel mode layerCVE-2026-47522 · NVIDIA GPU Display Driver kernel mode layer (input validation)Medium
- NVIDIA GPU driver: out-of-bounds read in the kernel mode layerCVE-2026-47524 · NVIDIA GPU Display Driver kernel mode layer (out-of-bounds read)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.