CVE-2022-22756: Code Injection
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-22756?
The severity of CVE-2022-22756 is medium with a value of 4.
Which software is affected by CVE-2022-22756?
Mozilla Firefox ESR version 91.6, Mozilla Firefox version up to exclusive 97, and Mozilla Thunderbird version 91.6 are affected by CVE-2022-22756.
How can CVE-2022-22756 be exploited?
CVE-2022-22756 can be exploited by convincing a user to drag and drop an image to their desktop or other folder, which can result in the object being changed into an executable script that runs arbitrary code when clicked.
Is there a remedy available for CVE-2022-22756?
Yes, Mozilla provides a remedy for CVE-2022-22756.
Where can I find more information about CVE-2022-22756?
You can find more information about CVE-2022-22756 in the Mozilla Bugzilla and Mozilla Security Advisories.