CVE-2022-45872 is a critical vulnerability affecting iTerm2 versions prior to 3.4.18, stemming from improper input validation of DECRQSS responses within the terminal emulator. Carrying a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to potentially execute arbitrary code or compromise system integrity via network vectors without requiring user interaction. While there are currently no known public exploits in major frameworks or evidence of active exploitation in the wild, the issue has been highlighted in recent security research regarding the mishandling of ANSI terminal escape sequences.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.18CPE matchmatch criteria | cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.