First published: Tue Feb 08 2022(Updated: )
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.6 | 91.6 |
<97 | 97 | |
<91.6 | 91.6 | |
<91.6 | 91.6 | |
Mozilla Firefox | <97.0 | |
Mozilla Firefox ESR | <91.6 | |
Mozilla Thunderbird | <91.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-22756 is medium with a value of 4.
Mozilla Firefox ESR version 91.6, Mozilla Firefox version up to exclusive 97, and Mozilla Thunderbird version 91.6 are affected by CVE-2022-22756.
CVE-2022-22756 can be exploited by convincing a user to drag and drop an image to their desktop or other folder, which can result in the object being changed into an executable script that runs arbitrary code when clicked.
Yes, Mozilla provides a remedy for CVE-2022-22756.
You can find more information about CVE-2022-22756 in the Mozilla Bugzilla and Mozilla Security Advisories.