vulnerability
MFSA2022-06 Thunderbird: Security Vulnerabilities fixed in Thunderbird 91.6 (CVE-2022-22753)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:H/Au:S/C:C/I:C/A:C) | Feb 8, 2022 | Feb 17, 2022 | Jan 28, 2025 |
Severity
7
CVSS
(AV:N/AC:H/Au:S/C:C/I:C/A:C)
Published
Feb 8, 2022
Added
Feb 17, 2022
Modified
Jan 28, 2025
Description
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox
Solution
mozilla-thunderbird-upgrade-91_6

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.