CVE-2025-66476
- From
- Luis Alvarado <luis.alvarado.torres@gmail.com>
- Date
- Jan 22, 2026, 16:40 UTC
- Message-ID
- <CALFwtBbK6sNo0swy5k_+jgcKQmOpw3b=o8_UKhvLhtYYLqoUow@mail.gmail.com>
Hello!
I need some help or guidance on how to remediate this vulnerability. We have a customer with Git, which includes VIM and is vulnerable to CVE-2025-66476. However, the GIT version for Windows was last updated in November 2025. How can I remediate this issue, is there a way to update VIM without updating git? if so , how.
File C:\Program Files\Git\usr\bin\vim.exe&; version `9.1.1914` is vulnerable to `CVE-2025-66476`, which exists in versions `< 9.1.1947`.
Thank you!
-- Luis A. Alvarado, M.S., CISSP, CEH, (ISC)² CAP, Security+ | IT Specialist (INFOSEC) This e-mail message and any attachment(s) are intended only for use by the addressee(s) named herein and may contain legally privileged and/or confidential information. If you are not the intended recipient of this e-mail message, you are hereby notified that any dissemination, distribution, or copying of this e-mail message, including any attachment(s), is strictly prohibited. If you have received this e-mail message in error, please immediately notify me by telephone or e-mail and permanently delete or destroy the original and any copy (electronic or printout) of this e-mail message, including any attachment(s).
... Truth is the only safe ground to stand on. - Anonymous