Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code
ID: 930d1532-6c28-5810-b382-433819808671
STIX ID: report--930d1532-6c28-5810-b382-433819808671
Feed Name: cybersecurityNews.com
A high-severity vulnerability (CVE-2025-66476) affecting Vim for Windows (versions before 9.1.1947) allows attackers to achieve arbitrary code execution by placing malicious executables in the current working directory; Vim previously searched the working directory before system directories when invoking external commands. The advisory notes a CVSS score of 7.8, describes common attack scenarios (e.g., cloned malicious repos triggering grep/make), and recommends immediate update to Vim/gVim version 9.1.1947 or later to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
