CVE-2016-1248 describes a critical vulnerability in Vim, specifically affecting versions prior to patch 8.0.0056, including Debian distributions. This flaw allows for arbitrary code execution when a user opens a specially crafted file containing malicious modeline options for 'filetype', 'syntax', or 'keymap'. With a CVSS v3 score of 7.8 (High), the vulnerability requires user interaction (UI:R) and local access (AV:L), but can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While there is no evidence of active exploitation in the wild (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with one Hacker News article and a high FAUCET Risk Score of 85/100, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.0.0055CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.