CVE-2023-4752

Executive Summary

CVE-2023-4752 is a use‑after‑free vulnerability in the Vim editor (versions prior to 9.0.1858). The flaw occurs during buffer handling, allowing an attacker to trigger a memory corruption that can lead to arbitrary code execution or a crash. The issue is not yet listed in the CISA KEV database. Users should upgrade to Vim 9.0.1858 or later to mitigate the risk.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2023-09-04T14:15:08.450 - Last Modified: 2026-09-17T17:59:05.257

Original Description: Use After Free in GitHub repository vim/vim prior to 9.0.1858.

"We must embrace pain and burn it as fuel for our journey."

— Kenji Miyazawa
Source: NVD