CVE-2023-31017: NVIDIA Virtual GPU

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

Affected products

  • NVIDIA Virtual GPU: before 13.9 (fixed in 13.9); from 14.0, before 15.4 (fixed in 15.4); from 16.0, before 16.2 (fixed in 16.2)

Published 2023-11-02. Last modified 2026-06-17.