NVIDIA has addressed multiple security vulnerabilities in its Delegated License Service, which could allow unauthenticated access, denial of service, and privilege escalation. According to security advisories, these flaws affected all appliance platforms running the Delegated License Service. One of the most critical issues, tracked as CVE-2025-23293, enables an attacker to perform actions as an authorized user, potentially leading to information disclosure. The vulnerabilities could be exploited by remote attackers, although CVE-2025-23293 is not remotely exploitable according to the official CVE entry. The flaws also include the possibility of unauthenticated access, which could allow attackers to bypass authentication mechanisms and gain unauthorized access to sensitive licensing functions. In addition, denial-of-service conditions could be triggered, potentially disrupting the availability of the licensing service for legitimate users. The vulnerabilities were disclosed and patched by NVIDIA, with security advisories urging customers to update their Delegated License Service installations to the latest version. The official CVE entry highlights the high severity of the privilege escalation and information disclosure risk, assigning a CVSS score of 8.7. No specific affected product versions were listed in the CVE database at the time of publication, but the advisories indicate that all appliance platforms are impacted. The vulnerabilities were reported to NVIDIA’s Product Security Incident Response Team (PSIRT), which coordinated the release of patches and public disclosure. Organizations using NVIDIA’s Delegated License Service are advised to review their deployments and apply the security updates promptly to mitigate the risk of exploitation. The flaws underscore the importance of securing licensing infrastructure, as compromise could lead to broader access within enterprise environments. No reports of active exploitation in the wild have been confirmed as of the latest advisories. The security community has emphasized the need for ongoing monitoring and prompt patch management in response to these types of vulnerabilities. NVIDIA’s response demonstrates a commitment to transparency and timely remediation of security issues affecting its enterprise customers. The incident serves as a reminder for organizations to maintain up-to-date inventories of third-party services and to prioritize patching of critical infrastructure components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
NVIDIA released fixes for multiple vulnerabilities in its Delegated License Service, including issues that could allow unauthenticated access and denial-of-service conditions. Public reporting on the patch release appeared on October 1, 2025.
NVIDIA disclosed CVE-2025-23293 affecting its Delegated Licensing Service, describing a vulnerability that could enable privilege escalation and information disclosure. The issue was publicly listed by late September 2025.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.