First published: Tue Jan 11 2022(Updated: )
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <96 | 96 |
<96 | 96 | |
Mozilla Firefox | <96.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22736 is a vulnerability in Firefox that could allow local privilege escalation when Firefox searches the current directory for system libraries in a world-writable directory.
CVE-2022-22736 affects Mozilla Firefox versions up to but not including version 96.0.
CVE-2022-22736 has a severity level of high, with a severity value of 7.
To fix CVE-2022-22736, update to Mozilla Firefox version 96.0 or higher.
Yes, CVE-2022-22736 only affects Firefox for Windows in a non-default installation.