PT-2025-48785 · Vim · Vim

Published

2025-12-02

·

Updated

2026-01-30

·

CVE-2025-66476

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim for Windows versions prior to 9.1.1947
Description Vim is a command line text editor. A flaw exists in Vim for Windows due to an uncontrolled search path issue. When using cmd.exe as a shell, Vim resolves external commands by searching the current working directory before system paths. This allows the execution of malicious executables placed in the same directory as the file being edited when Vim invokes tools such as findstr for :grep, external commands via :!, or compiler/:make commands. The issue enables attackers to execute arbitrary code with the user's privileges.
Recommendations Update Vim to version 9.1.1947 or later to address this issue.

Exploit

Fix

RCE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2025-66476
GHSA-G77Q-XRWW-P834
ZDI-25-1059

Affected Products

Vim