CVE-2022-28225: High severity yandex browser vulnerability
Published Jun 15, 2022
·Updated
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Affected Software
2 affected components
Yandex Yandex Browser<22.3.3.684
Microsoft Windows
Event History
Jun 15, 2022
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28225?
CVE-2022-28225 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2022-28225?
To fix CVE-2022-28225, update Yandex Browser to version 22.3.3.684 or later.
3
What are the affected systems for CVE-2022-28225?
CVE-2022-28225 affects Yandex Browser for Windows versions prior to 22.3.3.684.
4
Who can exploit CVE-2022-28225?
CVE-2022-28225 can be exploited by a local, low privileged attacker.
5
What kind of attack does CVE-2022-28225 allow?
CVE-2022-28225 allows arbitrary code execution with SYSTEM privileges.