CVE-2022-40733: Null Pointer Dereference
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40733?
CVE-2022-40733 is classified as a high severity vulnerability due to its potential impact on system stability.
How do I fix CVE-2022-40733?
To mitigate CVE-2022-40733, users should update to the latest patched version of Windows 11 or Windows Server 2022 as provided by Microsoft.
What products are affected by CVE-2022-40733?
CVE-2022-40733 affects Microsoft Windows 11 and Microsoft Windows Server 2022.
What type of attack can exploit CVE-2022-40733?
CVE-2022-40733 can be exploited through a specially-crafted set of syscalls that can lead to system reboots.
Is there any workaround for CVE-2022-40733?
There are currently no documented workarounds for CVE-2022-40733, making patching essential.