Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-22750
HistoryDec 22, 2022 - 12:00 a.m.

CVE-2022-22750

2022-12-2200:00:00
ubuntu.com
ubuntu.com
25
firefox
vulnerability
compromised
content process
resource handles
windows
macos
operating systems
cve-2022-22750

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

56.0%

By generally accepting and passing resource handles across processes, a
compromised content process might have confused higher privileged processes
to interact with handles that the unprivileged process should not have
access to.<br>This bug only affects Firefox for Windows and MacOS. Other
operating systems are unaffected.
. This vulnerability affects Firefox <
96.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

56.0%