CVE-2022-48386
published 2023-05-09CVE-2022-48386: the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed.
PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.09%
0.7th percentile
the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.14 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
| unisoc_technologies_co_ltd | sc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2q4q-4v3j-58f8: the apipe driver, there is a possible use after free due to a logic error
ghsa_unreviewed·2023-05-09
CVE-2022-48386 [MEDIUM] CWE-416 GHSA-2q4q-4v3j-58f8: the apipe driver, there is a possible use after free due to a logic error
the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed.
Microsoft
GitHub: CVE-2025-48386 Git Credential Helper Vulnerability
vendor_msrc·2025-07-08·CVSS 6.3
CVE-2025-48386 [MEDIUM] GitHub: CVE-2025-48386 Git Credential Helper Vulnerability
GitHub: CVE-2025-48386 Git Credential Helper Vulnerability
Description: CVE-2025-48386 is regarding a vulnerability in Git where the wincred credential helper uses a static buffer (target) as a unique key for storing and comparing against internal storage. This credential helper does not properly bounds check the available space remaining in the buffer before appending to it with wcsncat(), leading to potential buffer overflows. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in Git which address this vulnerability.
Please see CVE-2025-48386 for more information.
Visual Studio: Visual Studio
GitHub: GitHub
Customer Action Required: Yes
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 ver
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-09
Published