CVE-2022-40733

MEDIUM

Windows 11 22000.593 and Windows Server 2022 20348.643 - Denial of Service via DirectComposition Syscall

Title source: llm
STIX 2.1

Description

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.

References (1)

Core 1
Core References

Scores

CVSS v3 5.0
EPSS 0.0082
EPSS Percentile 52.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (2)
microsoft/windows_11_21h2 10.0.22000.593
microsoft/windows_server_2022 10.0.20348.643
Published Dec 18, 2024
Tracked Since Feb 18, 2026