CVE-2022-2200: High severity firefox esr vulnerability
Published Jun 28, 2022
·Updated
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution.
Affected Software
7 affected componentsFixes available
Mozilla Firefox ESR<91.11
91.11
Mozilla Thunderbird<102
102
Mozilla Thunderbird<91.11
91.11
Mozilla Firefox<102.0
Mozilla Firefox ESR<91.11
Mozilla Thunderbird<91.11
Mozilla Firefox<102
102
Event History
Jun 28, 2022
CVE Published
12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2200?
The severity of CVE-2022-2200 is medium.
2
How does CVE-2022-2200 impact Mozilla Firefox ESR?
CVE-2022-2200 impacts Mozilla Firefox ESR versions up to and excluding 91.11.
3
How does CVE-2022-2200 impact Mozilla Thunderbird?
CVE-2022-2200 impacts Mozilla Thunderbird versions up to and excluding 102.
4
How can an attacker exploit CVE-2022-2200?
An attacker can exploit CVE-2022-2200 by corrupting the object prototype, allowing them to set undesired attributes on JavaScript objects and leading to privileged code execution.
5
Where can I find more information about CVE-2022-2200?
You can find more information about CVE-2022-2200 at the following references: [1] [2] [3].