CRITICAL

CVE-2022-45063

CVSS v3

9.8

CRITICAL

EPSS Score

22.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

Technical details

Published
11/10/2022

Frequently asked questions

What is CVE-2022-45063?

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

Is CVE-2022-45063 actively exploited?

Active exploitation of CVE-2022-45063 has not been confirmed. The EPSS score is 22.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-45063?

CVE-2022-45063 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-45063 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.