CVE-2022-28226
HIGHYandex Browser < 22.3.3.801 - Exposure to Wrong Actor
Title source: ruleDescription
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Scores
CVSS v3
7.8
EPSS
0.0010
EPSS Percentile
26.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-668
Status
published
Affected Products (1)
yandex/yandex_browser
< 22.3.3.801
Timeline
Published
Jun 15, 2022
Tracked Since
Feb 18, 2026