Access Violation Vulnerability in Windows 11 and Server 2022 DirectComposition
CVE-2022-40733

5MEDIUM

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
18 December 2024

What is CVE-2022-40733?

CVE-2022-40733 is a critical access violation vulnerability found in the DirectComposition functionality of the win32kbase.sys driver, specifically affecting Windows 11 and Windows Server 2022. When a user executes specially-crafted syscalls, it can cause the system to reboot by triggering a Denial of Service (DoS) condition. Unprivileged users who can exploit this vulnerability may disrupt system operations, emphasizing the importance of timely updates and patches.

Affected Version(s)

Windows Build 22000.593

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Jaewon Min of Cisco Talos.
.