CVE-2022-22753
HIGHFirefox < 97.0 and Firefox ESR < 91.6 - Time-of-Check Time-of-Use Race Condition in Maintenance Service
Title source: llmDescription
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
References (4)
Core 4
Core References
Exploit, Issue Tracking, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1732435
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-04/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-05/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-06/
Scores
CVSS v3
7.1
EPSS
0.0037
EPSS Percentile
59.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-367
Status
published
Products (3)
mozilla/firefox
< 97.0
mozilla/firefox_esr
< 91.6
mozilla/thunderbird
< 91.6
Published
Dec 22, 2022
Tracked Since
Feb 18, 2026