7.1
CVSSv3

CVE-2022-22753

Published: 22/12/2022 Updated: 29/12/2022
CVSS v3 Base Score: 7.1 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox_esr

mozilla thunderbird

Vendor Advisories

Mozilla Foundation Security Advisory 2022-05 Security Vulnerabilities fixed in Firefox ESR 916 Announced February 8, 2022 Impact high Products Firefox ESR Fixed in Firefox ESR 916 ...
Mozilla Foundation Security Advisory 2022-04 Security Vulnerabilities fixed in Firefox 97 Announced February 8, 2022 Impact high Products Firefox Fixed in Firefox 97 ...
Mozilla Foundation Security Advisory 2022-06 Security Vulnerabilities fixed in Thunderbird 916 Announced February 8, 2022 Impact high Products Thunderbird Fixed in Thunderbird 916 ...