Loading cryptocurrency prices...

New NVIDIA Triton AI Server Bugs Allow Full Remote System Takeover

Critical Security Flaws in NVIDIA Triton Inference Server Allow Remote Takeover of AI Systems

  • Researchers disclosed serious security issues in the NVIDIA Triton Inference Server used for AI models.
  • The vulnerabilities could allow attackers to take full control of servers remotely and without credentials.
  • Three flaws in the server’s Python backend could be chained for remote code execution or data theft.
  • NVIDIA fixed the issues in version 25.07 and addressed three additional critical bugs.
  • There are no reports of attacks so far, but users are urged to update for protection.

A set of security flaws was recently found in the NVIDIA Triton Inference Server, an open-source platform that runs Artificial Intelligence (AI) models at scale on Windows and Linux. According to researchers at Wiz, these problems could let a remote attacker take over a vulnerable server, gaining full control without needing to log in.

- Advertisement -

The three main vulnerabilities, identified as CVE-2025-23319 (CVSS 8.1), CVE-2025-23320 (CVSS 7.5), and CVE-2025-23334 (CVSS 5.9), affect the Triton server’s Python backend. One flaw allows out-of-bounds writing, another can exceed the server’s memory limits, and the third enables reading out-of-bounds memory. Together, these issues could result in attackers executing their own code, denying service, or stealing information.

“When chained together, these flaws can potentially allow a remote, unauthenticated attacker to gain complete control of the server, achieving remote code execution (RCE),” explained Wiz’s Ronen Shustin and Nir Ohfeld in their report.

The vulnerabilities are rooted in how the Python backend handles requests for AI models from frameworks like PyTorch and TensorFlow. Attackers could use one weakness to leak the server’s private memory region name, then apply the other flaws to take over the system. This risk includes theft of AI models, exposure of sensitive data, or changing the results that AI models generate.

In its August security bulletin, NVIDIA also addressed three additional issues: CVE-2025-23310, CVE-2025-23311, and CVE-2025-23317. These could let attackers execute their own code, cause denial of service, expose information, or tamper with data if left patched.

- Advertisement -

There is no current evidence of these vulnerabilities being used in real attacks. Users of the Triton Inference Server are advised to update to version 25.07 or later for full protection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Peraire-Bueno Brothers Face Trial for $25M Ethereum MEV Exploit

The trial of two brothers accused of a $25 million exploit on the Ethereum...

US Seizes $14B in Bitcoin—Debate Rages Over Reserve or Restitution

The U.S. Department of Justice seized $14.4 billion in Bitcoin from the alleged leader...

OpenAI Faces Race to Bridge Revenue Gap in Trillion Dollar Gamble

OpenAI plans to spend over $1 trillion on Artificial Intelligence development and infrastructure over...

Altcoins Surge as Fed Signals Rate Cut; Bitcoin Eyes $130K Upside

Altcoins, including Ethereum and Solana, led gains as cryptocurrency markets rebounded mid-week. Federal Reserve signals...

Bitcoin Stabilizes as Musk Sparks Rally, Fed Signals Dovish Turn

Bitcoin steadied at around $112,000 after recent market volatility. Elon Musk made a bullish move...
- Advertisement -

Must Read

7 Best NFT Marketplaces for Every Need

Open Sea | Pianity | Foundation | Magic Eden | SuperRare | Rarible | Theta Drop | Other Platforms | About NFTs | FAQ...