CVE-2022-22736: High severity firefox vulnerability
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.. This vulnerability affects Firefox < 96.
Other sources
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-22736?
CVE-2022-22736 is a vulnerability in Firefox that could allow local privilege escalation when Firefox searches the current directory for system libraries in a world-writable directory.
Which software versions are affected by CVE-2022-22736?
CVE-2022-22736 affects Mozilla Firefox versions up to but not including version 96.0.
What is the severity level of CVE-2022-22736?
CVE-2022-22736 has a severity level of high, with a severity value of 7.
How can I fix CVE-2022-22736?
To fix CVE-2022-22736, update to Mozilla Firefox version 96.0 or higher.
Is Firefox for Windows the only affected in CVE-2022-22736?
Yes, CVE-2022-22736 only affects Firefox for Windows in a non-default installation.