ZDI-CAN-28569: ZDI-25-1059: Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vim for Windows. User interaction is required to exploit this vulnerability in that the target must open a malicious file and perform one of a set of specific actions in the editor. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-66476.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28569?
ZDI-CAN-28569 is categorized as a critical vulnerability due to its ability to allow remote code execution.
How do I fix ZDI-CAN-28569?
To mitigate ZDI-CAN-28569, ensure you update Vim for Windows to the latest version that addresses this vulnerability.
What types of actions are required to exploit ZDI-CAN-28569?
Exploiting ZDI-CAN-28569 requires the user to open a malicious file and perform specific actions within the Vim editor.
Who is affected by ZDI-CAN-28569?
ZDI-CAN-28569 affects installations of Vim specifically for Windows.
Can ZDI-CAN-28569 be exploited without user interaction?
No, ZDI-CAN-28569 requires user interaction to exploit the vulnerability, as the user must open a malicious file.