CVE-2022-3296
Executive Summary
CVE-2022-3296 is a stack-based buffer overflow in Vim (versions prior to 9.0.0577) that can be triggered by crafted input, potentially allowing an attacker to execute arbitrary code with the privileges of the Vim process. The vulnerability is exploitable via local or remote input, depending on how Vim is invoked, and could lead to privilege escalation or compromise of the host system. No current CISA KEV listing, but it remains a high‑severity risk for systems running affected Vim versions.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-09-25T17:15:09.457 - Last Modified: 2026-09-24T15:39:36.800
Original Description: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
"You, yourself, as much as anybody in the entire universe, deserve your love and affection."
— Buddha