#VU60398 Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-22756

 

#VU60398 Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-22756

Published: February 8, 2022


Vulnerability identifier: #VU60398
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22756
CWE-ID: CWE-357
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker execute arbitrary code.

The vulnerability exists due to browser fails to properly identify a malicious file during drag and drop operations. A remote attacker can trick the victim to drag and drop an image to their desktop or other folder and change the resulting object into an executable script which will be executed after the user clicked on it.


Remediation

Install updates from vendor's website.

External links