#VU59367 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2022-22743

 

#VU59367 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2022-22743

Published: January 11, 2022


Vulnerability identifier: #VU59367
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22743
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to an error when navigating from inside an iframe while requesting fullscreen access. A remote attacker can trick the victim to open a specially crafted web page,  and make the browser unable to leave fullscreen mode.

Successful exploitation of the vulnerability may allow an attacker to perform spoofing attack.


Remediation

Install updates from vendor's website.

External links