CVE-2022-28226: High severity yandex browser vulnerability
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28226?
CVE-2022-28226 is considered a local privilege escalation vulnerability due to its potential to allow arbitrary code execution with SYSTEM privileges.
How do I fix CVE-2022-28226?
Update Yandex Browser to version 22.3.3.801 or later to mitigate CVE-2022-28226.
Who is affected by CVE-2022-28226?
Users of Yandex Browser for Windows prior to version 22.3.3.801 are affected by CVE-2022-28226.
What makes CVE-2022-28226 a local privilege escalation vulnerability?
CVE-2022-28226 allows low privileged attackers to manipulate temporary files, gaining SYSTEM privileges during the update process.
Can CVE-2022-28226 be exploited remotely?
No, CVE-2022-28226 requires local access to the affected system to exploit.