logo

Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code

ID: 930d1532-6c28-5810-b382-433819808671

STIX ID: report--930d1532-6c28-5810-b382-433819808671

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

A high-severity vulnerability (CVE-2025-66476) affecting Vim for Windows (versions before 9.1.1947) allows attackers to achieve arbitrary code execution by placing malicious executables in the current working directory; Vim previously searched the working directory before system directories when invoking external commands. The advisory notes a CVSS score of 7.8, describes common attack scenarios (e.g., cloned malicious repos triggering grep/make), and recommends immediate update to Vim/gVim version 9.1.1947 or later to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.