CVE-2022-40733
CVSS 3.1 Score 5.0 of 10 (medium)
Details
Published Dec 18, 2024
CWE ID 476
Summary
CVE-2022-40733 is an access violation vulnerability affecting the DirectComposition functionality in the win32kbase.sys driver of Windows 11 version 22000.593 and Windows Server 2022 version 20348.643. By sending a specific sequence of syscalls, an unprivileged user can exploit this flaw, leading to a system reboot. The vulnerability poses a Denial of Service risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.