Vulnerability · NVD
CVE-2022-3775
CVE-2022-3775 : high severity (CVSS 7.1). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 7.1
- Exploitation
- 0.9 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.
Show raw CVSS vector
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2022 (Server Core installation) Fixed in 10.0.20348.2655
- Windows Server 2022 Fixed in 10.0.25398.1085
- Windows Server 2019 Fixed in 10.0.17763.6189
- Windows Server 2016 Fixed in 10.0.14393.7259
- Windows 11 24H2 · 2024-H2 Fixed in 10.0.26100.1457
- Windows 11 23H2 · 2023-H2 Fixed in 10.0.22631.4037
- Windows 11 22H2 · 2022-H2 Fixed in 10.0.22621.4037
- Windows 11 21H2 · 2021-H2 Fixed in 10.0.22000.3147
- Windows 10 22H2 · 2022-H2 Fixed in 10.0.19045.4780
- Windows 10 21H2 · 2021-H2 Fixed in 10.0.19044.4780
- Windows 10 1809 · 2018-09 Fixed in 10.0.17763.6189
- Windows 10 1607 · 2016-07 Fixed in 10.0.14393.7259
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.