CVE-2022-40732

CVSS 3.1 Score 5 of 10 (medium)

Details

Published Dec 18, 2024
CWE ID 476

Summary

CVE-2022-40732 is a newly discovered access violation vulnerability that affects the DirectComposition functionality of win32kbase.sys driver in Windows 11 version 22000.593 and Windows Server 2022 version 20348.643. This issue, which exists in driver version 10.0.22000.593 and 10.0.20348.643, can be exploited by an unprivileged user through a specific set of syscalls. Successful exploitation leads to a system reboot, causing a Denial of Service condition. It is crucial that affected systems are updated as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share