CVE-2022-40732
Last modified
CVE-2022-40732 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 11 21h2 | 10.0.22000.593 |
| Microsoft | Windows Server 2022 | 10.0.20348.643 |
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1514Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-40732?
How severe is CVE-2022-40732?
How do I fix CVE-2022-40732?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40721Arbitrary file upload vulnerability in php uploader9.8
- CVE-2022-40722A misconfiguration of RSA padding implemented in the PingID …5.8
- CVE-2022-40723The PingID RADIUS PCV adapter for PingFederate, which suppor…6.5
- CVE-2022-40724The PingFederate Local Identity Profiles '/pf/idprofile.ping…8.8
- CVE-2022-40725PingID Desktop prior to the latest released version 1.7.4 co…6.1
- CVE-2022-4073Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40733An access violation vulnerability exists in the DirectCompos…6.5
- CVE-2022-40734UniSharp laravel-filemanager (aka Laravel Filemanager) befor…6.5
- CVE-2022-40735The Diffie-Hellman Key Agreement Protocol allows use of long…7.5
- CVE-2022-40736An issue was discovered in Bento4 1.6.0-639. There ie excess…6.5
- CVE-2022-40737An issue was discovered in Bento4 through 1.6.0-639. A buffe…6.5
- CVE-2022-40738An issue was discovered in Bento4 through 1.6.0-639. A NULL …6.5
Are you affected by CVE-2022-40732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
