#VU59369 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2022-22741

 

#VU59369 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2022-22741

Published: January 11, 2022


Vulnerability identifier: #VU59369
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22741
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to an error resizing a popup while requesting fullscreen access. A remote attacker can trick the victim to open a specially crafted web page,  and make the browser unable to leave fullscreen mode.

Successful exploitation of the vulnerability may allow an attacker to perform spoofing attack.

Remediation

Install updates from vendor's website.

External links