First published: Tue Feb 08 2022(Updated: )
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.This bug only affects Firefox on Windows. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.6 | 91.6 |
<97 | 97 | |
<91.6 | 91.6 | |
<91.6 | 91.6 | |
Mozilla Firefox | <97.0 | |
Mozilla Firefox ESR | <91.6 | |
Mozilla Thunderbird | <91.6 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID of this bug is CVE-2022-22753.
The severity of CVE-2022-22753 is high.
Firefox ESR versions up to 91.6, Thunderbird versions up to 91.6, and Firefox versions up to 97 are affected by CVE-2022-22753.
This vulnerability can be exploited by abusing the Time-of-Check Time-of-Use bug in the Maintenance (Updater) Service to grant users write access to an arbitrary directory, potentially leading to escalation of privileges.
No, this bug only affects Firefox on Windows. Other operating systems are unaffected.