CVE-2023-1127
📛 CVE Title
Divide By Zero in vim/vim
Description
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- @huntrdev
- CVSS severity
- HIGH
- CVSS score
- 7.3 / 10
- CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H- Effective score
- 7.3 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important
- CWE(s)
-
CWE-369 - Reserved
- 2023-03-01
- Published
- 2023-03-01 01:00 UTC
- Last updated
- 2025-03-07 17:39 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/1xxx/CVE-2023-1127.json
- Linked Threat
- CVE-2023-1127 — Divide By Zero in vim/vim
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-23410 - Assigner
- @huntrdev
- Published
- Mar 1, 2023, 12:00:00 AM
- Updated
- Mar 7, 2025, 4:39:25 PM
- EUVD base score (CVSS 3.0)
-
7.3 / 10
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.0500
- Vendors
- vim
- Products
-
vim/vim (unspecified <9.0.1367)
- Aliases
-
GHSA-wvg5-x3jq-vp4g
ENISA description: Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
EUVD references (5)
- https://huntr.dev/bounties/2d4d309e-4c96-415f-9070-36d0815f1beb
- https://github.com/vim/vim/commit/e0f869196930ef5f25a0ac41c9215b09c9ce2d3c
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDVN5HSWPNVP4QXBPCEGZDLZKURLJWTE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ6TMKKBXHGVUHWFGM4X46VIJO7ZAG2W/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 01:48 UTC (source: CVRF).
- MS severity
- Important
- MS CVSS base score
- 7.8 / 10 (temporal 7.8)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - Release
- 2023-Mar
Microsoft remediations / KB articles (2)
- CBL-Mariner Releases — Vendor Fix / Security Update (fixed build 9.0.1402-1)
- https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade — None Available / CBL-Mariner Releases
Microsoft FAQ (1)
Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| vim | vim/vim |
unspecified (affected)
|
— |
Vendor references (5)
References embedded in the original CVE record by the assigning CNA.
- https://huntr.dev/bounties/2d4d309e-4c96-415f-9070-36d0815f1beb
- https://github.com/vim/vim/commit/e0f869196930ef5f25a0ac41c9215b09c9ce2d3c
- FEDORA-2023-27958e9307 vendor-advisory
- FEDORA-2023-ccf283d7e1 vendor-advisory
- FEDORA-2023-030318ca00 vendor-advisory
Web references (9)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- MSRC update guide: CVE-2023-1127 msrc
- None Available msrc
- https://security.alpinelinux.org/vuln/CVE-2023-1127 rapid7:security.alpinelinux.org
- https://alas.aws.amazon.com/AL2023/ALAS-2023-137.html rapid7:alas.aws.amazon.com
- http://cwe.mitre.org/data/definitions/369.html rapid7:cwe.mitre.org
- https://www.dell.com/support/kbdoc/en-us/000218046/dsa-2023-366-dell-powerstore-family-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://attackerkb.com/topics/CVE-2023-1127 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-23410 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2023-1127 rapid7:www.cve.org
Remediations (14)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.bleepingcomputer.com
Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code.
2026-06-02 14:57 UTC -
web:www.tenable.com
Microsoft patched 57 CVEs in its November 2023 Patch Tuesday release, with three rated critical and 54 rated important. We omitted one vulnerability from our counts this month, CVE - 2023 -24023, a Bluetooth Vulnerability as this flaw was reported through MITRE.
2026-06-02 14:57 UTC -
web:www.elevenforum.com
November 2023 Security Updates This release consists of the following 63 Microsoft CVEs : Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations ? Microsoft Dynamics CVE - 2023 -36007 Microsoft Edge (Chromium-based) CVE - 2023 -36014 Microsoft Dynamics CVE - 2023 -36016 Windows...
2026-06-02 14:57 UTC -
web:cybersecuritynews.com
Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, targeting a critical installation failure that affected users following the May 2026 Patch Tuesday release.
2026-06-02 14:57 UTC -
web:www.cisa.gov
Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287
2026-05-22 05:38 UTC -
web:www.cisco.com
This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.
2026-05-22 05:38 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-22 05:38 UTC -
web:www.pcworld.com
Windows 11's Secure Boot fix update finally rolls out to more PCs Important security certificates for Windows 11 will soon expire for many users.
2026-05-22 05:38 UTC -
web:www.windowslatest.com
Windows 11 March 2026 Patch Tuesday update adds Emoji 16.0, Sysmon, network speed test, reliability improvements, and security fixes.
2026-05-22 05:38 UTC -
web:blog.qualys.com
Qualys highlights November 2023 Patch Tuesday updates from Microsoft and Adobe, covering vulnerabilities needing prompt remediation .
2026-05-22 05:38 UTC -
web:www.zdnet.com
Install Microsoft's emergency Windows patch now - what it fixes and why it was rushed out Microsoft issued an out-of-band fix after its latest update introduced a nasty surprise.
2026-05-22 05:38 UTC -
web:cybersecuritynews.com
Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.
2026-05-22 05:38 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:38 UTC -
web:www.bleepingcomputer.com
Microsoft has released an out-of-band cumulative update to fix a known issue causing the November 2025 KB5068966 hotpatch update to reinstall on Windows 11 systems repeatedly.
2026-05-22 05:38 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-1127.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:32:46.417Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://huntr.dev/bounties/2d4d309e-4c96-415f-9070-36d0815f1beb"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/vim/vim/commit/e0f869196930ef5f25a0ac41c9215b09c9ce2d3c"
},
{
"name": "FEDORA-2023-27958e9307",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDVN5HSWPNVP4QXBPCEGZDLZKURLJWTE/"
},
{
"name": "FEDORA-2023-ccf283d7e1",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ6TMKKBXHGVUHWFGM4X46VIJO7ZAG2W/"
},
{
"name": "FEDORA-2023-030318ca00",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1127",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-07T16:39:11.953023Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-07T16:39:25.382Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "vim/vim",
"vendor": "vim",
"versions": [
{
"lessThan": "9.0.1367",
"status": "affected",
"version": "unspecified",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Divide By Zero in GitHub repository vim/vim prior to 9.0.1367."
}
],
"metrics": [
{
"cvssV3_0": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-369",
"description": "CWE-369 Divide By Zero",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-04-02T00:00:00.000Z",
"orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"shortName": "@huntrdev"
},
"references": [
{
"url": "https://huntr.dev/bounties/2d4d309e-4c96-415f-9070-36d0815f1beb"
},
{
"url": "https://github.com/vim/vim/commit/e0f869196930ef5f25a0ac41c9215b09c9ce2d3c"
},
{
"name": "FEDORA-2023-27958e9307",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDVN5HSWPNVP4QXBPCEGZDLZKURLJWTE/"
},
{
"name": "FEDORA-2023-ccf283d7e1",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ6TMKKBXHGVUHWFGM4X46VIJO7ZAG2W/"
},
{
"name": "FEDORA-2023-030318ca00",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/"
}
],
"source": {
"advisory": "2d4d309e-4c96-415f-9070-36d0815f1beb",
"discovery": "EXTERNAL"
},
"title": "Divide By Zero in vim/vim"
}
},
"cveMetadata": {
"assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"assignerShortName": "@huntrdev",
"cveId": "CVE-2023-1127",
"datePublished": "2023-03-01T00:00:00.000Z",
"dateReserved": "2023-03-01T00:00:00.000Z",
"dateUpdated": "2025-03-07T16:39:25.382Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}