Access Violation Vulnerability in Windows 11 and Windows Server 2022 DirectComposition Driver
CVE-2022-40732

5MEDIUM

Key Information:

Vendor
Microsoft
Status
Windows
Vendor
CVE Published:
18 December 2024

Summary

CVE-2022-40732 is identified as an access violation vulnerability found in the DirectComposition functionality of the win32kbase.sys driver within Windows 11 (version 22000.593) and Windows Server 2022 (version 20348.643). When exploited, this vulnerability allows an unprivileged user to execute specially-crafted code, potentially leading to a Denial of Service (DoS) condition, which can result in system instability and unexpected reboots. It is crucial for users of the affected versions to apply necessary security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Windows Build 22000.593

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Discovered by Jaewon Min of Cisco Talos.
.