CVE-2023-1170

Executive Summary

CVE-2023-1170 is a heap‑based buffer overflow in the Vim editor (versions <9.0.1376). An attacker can trigger the overflow via crafted input, potentially leading to arbitrary code execution or denial of service. The flaw resides in the handling of certain command arguments, allowing memory corruption. Mitigation involves updating to Vim 9.0.1376 or later, or applying vendor‑supplied patches. The vulnerability is not yet listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 6.6 (MEDIUM) - Published: 2023-03-03T23:15:11.830 - Last Modified: 2026-09-18T15:37:44.827

Original Description: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

"Do, or do not. There is no try."

— Yoda
Source: NVD