Access Violation Vulnerability in Windows 11 and Windows Server 2022 DirectComposition Driver
CVE-2022-40732
5MEDIUM
Summary
CVE-2022-40732 is identified as an access violation vulnerability found in the DirectComposition functionality of the win32kbase.sys driver within Windows 11 (version 22000.593) and Windows Server 2022 (version 20348.643). When exploited, this vulnerability allows an unprivileged user to execute specially-crafted code, potentially leading to a Denial of Service (DoS) condition, which can result in system instability and unexpected reboots. It is crucial for users of the affected versions to apply necessary security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Windows Build 22000.593
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Discovered by Jaewon Min of Cisco Talos.