CVE-2022-28226

HIGH

Yandex Browser < 22.3.3.801 - Exposure to Wrong Actor

Title source: rule

Description

Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 26.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-668
Status published

Affected Products (1)

yandex/yandex_browser < 22.3.3.801

Timeline

Published Jun 15, 2022
Tracked Since Feb 18, 2026