CVE-2022-3324
Executive Summary
Stack-based buffer overflow in Vim (v9.0 and earlier) allows attackers to trigger arbitrary code execution by supplying crafted input, such as a malicious file or command, leading to potential remote code execution. The vulnerability exists in the parsing of certain input types and can be exploited without authentication. It is not currently listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-09-27T23:15:15.927 - Last Modified: 2026-09-24T15:38:04.713
Original Description: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
"Without this playing with fantasy no creative work has ever yet come to birth. The debt we owe to the play of the imagination is incalculable."
— Carl Jung