CVE-2025-23266
CRITICAL 9.0EPSS 3.1%
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
- CVSS v3.1
- 9.0 CRITICAL
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 9.0 CRITICAL
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS
- 3.11% chance of exploitation in the next 30 days, 87th percentile
- Published
- 2025-07-17
- Updated
- 2026-02-26
Proof-of-concept exploits (4)
- Mindasy/cve-2025-23266-migration-bypass1★ · 2025-09-04
- jpts/cve-2025-23266-poc14★ · 2025-07-19
- mrk336/CVE-2025-232661★ · 2025-09-07
- r0binak/CVE-2025-232661★ · 2026-03-19