Lucene search

K
cvelistMozillaCVELIST:CVE-2022-22736
HistoryDec 22, 2022 - 12:00 a.m.

CVE-2022-22736

2022-12-2200:00:00
mozilla
www.cve.org
5
firefox
windows
local privilege escalation
vulnerability
cve-2022-22736

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.. This vulnerability affects Firefox < 96.

CNA Affected

[
  {
    "vendor": "Mozilla",
    "product": "Firefox",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "96",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%