CVE-2022-0517: Malicious File Upload
Published Feb 23, 2022
·Updated
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege.
Affected Software
2 affected componentsFixes available
Mozilla VPN<2.7.1
Mozilla Mozilla VPN<2.7.1
2.7.1
Event History
Feb 23, 2022
CVE Published
12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-0517?
CVE-2022-0517 is a vulnerability in Mozilla VPN that allows an attacker with limited privileges to launch arbitrary code with SYSTEM privilege.
2
What is affected by CVE-2022-0517?
Mozilla VPN versions earlier than 2.7.1 are affected by CVE-2022-0517.
3
How can an attacker exploit CVE-2022-0517?
By leveraging the ability to load an OpenSSL configuration file from an unsecured directory, an attacker with limited privileges can launch arbitrary code with SYSTEM privilege.
4
What is the severity of CVE-2022-0517?
CVE-2022-0517 has a severity rating of high, with a severity value of 7.
5
How can I fix CVE-2022-0517?
To fix CVE-2022-0517, update Mozilla VPN to version 2.7.1 or later.