CVE-2022-40732
MEDIUMWindows 11 22000.593 and Windows Server 2022 20348.643 - Denial of Service via DirectComposition Syscall
Title source: llmDescription
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1514
Scores
CVSS v3
5.0
EPSS
0.0074
EPSS Percentile
50.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (2)
microsoft/windows_11_21h2
10.0.22000.593
microsoft/windows_server_2022
10.0.20348.643
Published
Dec 18, 2024
Tracked Since
Feb 18, 2026