CVE-2022-22736

If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:47

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1742692 - Exploit, Issue Tracking, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1742692 - Exploit, Issue Tracking, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-01/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-01/ - Vendor Advisory
Summary
  • (es) Si Firefox se instaló en un directorio escribible, podría producirse una escalada de privilegios locales cuando Firefox busque librerías del sistema en el directorio actual. Sin embargo, el directorio de instalación no es escribible de forma predeterminada.<br>*Este error sólo afecta a Firefox para Windows en una instalación no predeterminada. Otros sistemas operativos no se ven afectados.*. Esta vulnerabilidad afecta a Firefox &lt; 96.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-16 16:15


NVD link : CVE-2022-22736

Mitre link : CVE-2022-22736

CVE.ORG link : CVE-2022-22736


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-427

Uncontrolled Search Path Element