CVE-2022-22753
Summary
| CVE | CVE-2022-22753 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2022-12-29 23:03:00 UTC |
| Description | A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 376387 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-04)
- 376388 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-05)
- 376402 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2022-06)
- 502385 Alpine Linux Security Update for thunderbird
- 502688 Alpine Linux Security Update for firefox
- 505452 Alpine Linux Security Update for thunderbird
- 710574 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202202-03)
- 751758 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2022:0559-1)
- 751761 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:0565-1)
- 751777 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:0676-1)
- 751786 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:0696-1)
- 751827 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2022:40696-1)
- 753305 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:14896-1)