CVE-2022-37173Incorrect Default Permissions in Gvim

Severity
7.8HIGHNVD
EPSS
0.1%
top 84.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateAug 31

Description

An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDvim/gvim9.0.0000

🔴Vulnerability Details

1
GHSA
GHSA-j476-559m-2j85: An issue in the installer of gvim 92022-08-31