Mozilla Fixes Firefox Privilege Escalation Vulnerability

Share post:

Mozilla has fixed the privilege escalation vulnerability in the Firefox 97 security update known as CVE-2022-22753.

Once the vulnerability is successfully exploited on unpatched systems, attackers can escalate their privileges to the highest level of privileges on a Windows system. Mozilla says the flaw “only affects Firefox on Windows. Other operating systems are unaffected.”

Other fixes that Firefox 97 fixes include several memory safety bugs found by Mozilla developers and the community in Firefox 96 and Firefox ESR 91.5.

Mozilla warned that systems running vulnerable versions of Firefox could be exploited to cause a heap-based buffer overflow.

Some likely consequences are program crashes, the execution of arbitrary code, and the bypass of security software once code execution is achieved.

Affected are all PDF viewers and email clients using NSS versions that have been approved for signature verification since October 2012.

Other updates to Firefox 97 include support for the new style of scrollbars on Windows 11. The new version removes support for direct generation of PostScript for printing on Linux. Printing to PostScript is still available as a supported option, however.

For more information, read the original story in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cloudflare Launches Open Source Tool for Secure, Keyless SSH Authentication

Cloudflare has released an open-source tool called OPKSSH (OpenPubkey SSH), which allows developers and IT teams to use...

US Defence Contractor Fined 4.6 Million For Failing To Meet Cyber Security Requirements.

A U.S. defence contractor, MORSE Corp, has agreed to pay $4.6 million to settle allegations of failing to...

Tech Aide on U.S. Government Efficiency Team Linked to Cybercrime Group

A 19-year-old staffer working on the U.S. Department of Government Efficiency (DOGE) initiative has been linked to a...

Top U.S. Security Officials Have Even More Data Exposed Through Public Apps, Chats, and Data Leaks

A new investigation has revealed that personal information belonging to senior U.S. security officials — including active phone...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways