First published: Tue Jul 26 2022(Updated: )
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <102.1 | 102.1 |
Firefox | <103 | 103 |
Firefox ESR | <102.1 | 102.1 |
Firefox | <103.0 | |
Firefox ESR | <102.1 | |
Thunderbird | <102.1 | |
Microsoft Windows Operating System | ||
All of | ||
Any of | ||
Firefox | <103.0 | |
Firefox ESR | <102.1 | |
Thunderbird | <102.1 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-36314 has a moderate severity rating, as it may lead to unexpected network requests from the operating system.
To fix CVE-2022-36314, users should upgrade to Firefox version 103 or Firefox ESR version 102.1 or later.
CVE-2022-36314 affects Firefox and Firefox ESR for Windows, as well as Thunderbird versions prior to 102.1.
CVE-2022-36314 allows attackers to create a Windows shortcut with a remote path, resulting in unintended network requests.
No, CVE-2022-36314 only affects Firefox and Firefox ESR on Windows systems, with no impact on other operating systems.