CVE-2022-0517
published 2022-12-22CVE-2022-0517: Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.3th percentile
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | mozilla_vpn | >= unspecified < 2.7.1 | 2.7.1 |
| mozilla | vpn | < 2.7.1 | 2.7.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vgm-pr2v-749c: Mozilla VPN can load an OpenSSL configuration file from an unsecured directory
ghsa_unreviewed·2022-12-22
CVE-2022-0517 [HIGH] CWE-434 GHSA-4vgm-pr2v-749c: Mozilla VPN can load an OpenSSL configuration file from an unsecured directory
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.
Mozilla
Mozilla Foundation Security Advisory 2022-08: CVE-2022-0517
vendor_mozilla·CVSS 7.8
CVE-2022-0517 [HIGH] Mozilla Foundation Security Advisory 2022-08: CVE-2022-0517
Mozilla Foundation Security Advisory 2022-08
CVE: CVE-2022-0517
Product: Mozilla VPN
Impact: high
Fixed in: Mozilla VPN 2.7.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published