Memory Corruption Vulnerability in vim 9.1.0000 by Vim
CVE-2025-9389

4.8MEDIUM

Key Information:

Vendor

Vim

Status
Vendor
CVE Published:
24 August 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-9389?

A memory corruption vulnerability has been discovered in vim 9.1.0000, specifically within the function __memmove_avx_unaligned_erms found in memmove-vec-unaligned-erms.S. This flaw allows for potential exploitation through local attack vectors. Although some users report difficulty in reproducing the issue, especially when colorization features are active, the exploit is publicly available, which heightens the risk for systems running the affected version. It is critical for users and administrators to be aware of this vulnerability and to evaluate possible impacts on their systems.

Affected Version(s)

vim 9.1.0000

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xudong Cao
Meng Xu
.
CVE-2025-9389 : Memory Corruption Vulnerability in vim 9.1.0000 by Vim