Crash or code execution via malformed string constants
Published Aug 1, 2022 · Updated Aug 3, 2024
Heap-based buffer overflow in Vim before 9.0.0102 allows local users to crash the editor or execute code via a crafted Vim script. The eval_string function fails to skip an entire form, treats a brace inside it as interpolation syntax, and advances beyond the allocated string buffer. Exploitation requires victim interaction with crafted content, and resulting code runs with the account privileges of the Vim process.
Summary
What happened
Heap-based buffer overflow in Vim before 9.0.0102 allows local users to crash the editor or execute code via a crafted Vim script. The eval_string function fails to skip an entire form, treats a brace inside it as interpolation syntax, and advances beyond the allocated string buffer. Exploitation requires victim interaction with crafted content, and resulting code runs with the account privileges of the Vim process.
The record
- CVE
- CVE-2022-2580
- Published
- Aug 1, 2022
- Updated
- Aug 3, 2024
- Vendor
- Vim
- Product
- Vim
- Classifications
- CWE-122, T1203
- Attack vector
- local
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 1, 2022CVE publishedPublication date reported by the CVE source.
- Aug 3, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=unspecified <9.0.0102
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo