CVE-2022-40732: Null Pointer Dereference
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40732?
CVE-2022-40732 has been classified with a severity rating that indicates potential impact on system stability due to access violation.
How do I fix CVE-2022-40732?
To mitigate CVE-2022-40732, ensure your systems are updated with the latest patches released by Microsoft for Windows 11 and Windows Server 2022.
What systems are affected by CVE-2022-40732?
CVE-2022-40732 affects Microsoft Windows 11 and Microsoft Windows Server 2022.
What is the impact of CVE-2022-40732?
The impact of CVE-2022-40732 includes potential system reboot caused by specially crafted syscalls.
Is there a known exploit for CVE-2022-40732?
As of now, no publicly known exploits for CVE-2022-40732 have been reported, but the vulnerability poses a risk that should be addressed promptly.