#VU60398 Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-22756
Published: February 8, 2022
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker execute arbitrary code.
The vulnerability exists due to browser fails to properly identify a malicious file during drag and drop operations. A remote attacker can trick the victim to drag and drop an image to their desktop or other folder and change the resulting object into an executable script which will be executed after the user clicked on it.