CVE Tools

Description

vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.

In plain language

AI Worth attention

CVE-2016-1248 is a Vim bug where opening a carefully crafted text file can trick Vim into running arbitrary code via “modeline” settings; most small businesses should treat this as a medium-term risk and update Vim if you use it to open files from untrusted sources.

Executive summary

CVE-2016-1248 is a Vim input-validation flaw (CWE-20) in how “filetype”, “syntax”, and “keymap” modeline values are validated; a specially crafted modeline in a text file can lead to arbitrary code execution when the file is opened in Vim, and the fixed version is 8.0.0056.

If affected, business impact
Arbitrary code executionFull account compromiseRansomware riskData theft risk

What to do now

  1. Check which Vim you run (for example, run vim --version) and confirm whether it is older than 8.0.0056.
  2. If your Vim version is older than 8.0.0056, plan an upgrade to Vim 8.0.0056 or later.
  3. Pay special attention to workflows where staff open files from outside your organization (email attachments, downloaded archives, shared documents) in Vim, and restrict that if possible until you upgrade.
  4. After upgrading, test that your usual Vim usage still works (especially any reliance on modelines or filetype/syntax auto-detection) and remove any unusually configured modeline behavior if you had it customized.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

vim
oss-projectaka vim/vim, vi, gvim
debian
oss-project·GBaka debian gnu/linux
and 1 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Initial Access
View detailed technique mapping

References

and 10 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-1248 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows