Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2022-22753

HIGH 7.1

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

Attack vector : Network
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS 0.63% exploit very unlikely percentile 47.0%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

NVD references 4 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (1)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
<91.6
View on NVD ↗ Advisory · bugzilla.mozilla.org Advisory · www.mozilla.org