CVSS v3
9.8
CRITICAL
EPSS Score
22.4%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
Active exploitation of CVE-2022-45063 has not been confirmed. The EPSS score is 22.4%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2022-45063 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).