An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
History

Fri, 20 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 22:45:00 +0000

Type Values Removed Values Added
Description An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published: 2024-12-18T22:35:34.539Z

Updated: 2024-12-20T17:22:31.797Z

Reserved: 2022-09-14T21:22:59.117Z

Link: CVE-2022-40733

cve-icon Vulnrichment

Updated: 2024-12-20T17:22:27.810Z

cve-icon NVD

Status : Received

Published: 2024-12-18T23:15:07.243

Modified: 2024-12-18T23:15:07.243

Link: CVE-2022-40733

cve-icon Redhat

No data.