PT-2025-48785 · Vim · Vim
Published
2025-12-02
·
Updated
2026-01-30
·
CVE-2025-66476
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vim for Windows versions prior to 9.1.1947
Description
Vim is a command line text editor. A flaw exists in Vim for Windows due to an uncontrolled search path issue. When using cmd.exe as a shell, Vim resolves external commands by searching the current working directory before system paths. This allows the execution of malicious executables placed in the same directory as the file being edited when Vim invokes tools such as findstr for :grep, external commands via :!, or compiler/:make commands. The issue enables attackers to execute arbitrary code with the user's privileges.
Recommendations
Update Vim to version 9.1.1947 or later to address this issue.
Exploit
Fix
RCE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vim