Impact
NVIDIA’s vGPU Virtual GPU Manager for Windows and Linux contains a kernel‑mode integer overflow that can corrupt memory when a guest VM performs certain operations. This vulnerability can allow a local attacker to execute arbitrary code, crash the host, or extract sensitive information from the system. The impact is substantial, potentially leading to full system takeover, data tampering and denial of service. The weakness is catalogued as CWE‑190, an integer overflow flaw.
Affected Systems
All NVIDIA products that rely on the vGPU Virtual GPU Manager, including GeForce, RTX, Quadro, NVS and Tesla GPUs, on both Windows and Linux platforms. Specific affected firmware or driver versions are not disclosed in the current data, so all deployments of the vGPU Manager should be considered at risk unless verified otherwise.
Risk and Exploitability
The CVSS score of 7.8 rates the issue as high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but kernel‑level integer overflows are historically exploitable with moderate effort. The attack vector involves a guest user executing code that triggers the overflow, leading to host kernel memory corruption. Successful exploitation would grant the attacker escalation of privileges and code execution on the host.
OpenCVE Enrichment