Impact
A flaw in Vim's netrw plugin allows a crafted filename containing quote characters and expression fragments to break out of the quoted context during mark/unmark operations, enabling arbitrary Vimscript execution. An attacker can then run shell commands with the privileges of the user running Vim, representing a serious local code‑execution risk.
Affected Systems
This vulnerability affects Red Hat products, including Red Hat Enterprise Linux versions 6 through 10 and Red Hat OpenShift Container Platform 4. Users running these distribution releases should verify the exact Vim package version for support.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is likely exploited by an attacker who can place a maliciously crafted filename on a filesystem the user can access, and then has the user browse the directory with Vim’s netrw plugin, leading to arbitrary Vimscript and shell execution as that user.
OpenCVE Enrichment
Ubuntu USN