CVE-2022-22753
published 2022-12-22CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This…
PriorityP337high7.1CVSS 3.1
AVNACHPRLUIRSUCHIHAH
EPSS
0.63%
46.2th percentile
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 97.0 | 97.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 97 | 97 |
| mozilla | firefox_esr | < 91.6 | 91.6 |
| mozilla | firefox_esr | >= unspecified < 91.6 | 91.6 |
| mozilla | thunderbird | < 91.6 | 91.6 |
| mozilla | thunderbird | >= unspecified < 91.6 | 91.6 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Privilege Escalation to SYSTEM on Windows via Maintenance Service
vendor_redhat·2022-02-08·CVSS 7.1
CVE-2022-22753 [HIGH] CWE-367 Mozilla: Privilege Escalation to SYSTEM on Windows via Maintenance Service
Mozilla: Privilege Escalation to SYSTEM on Windows via Maintenance Service
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
The Mozilla Foundation Security Advisory describes this flaw as:
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access. This bug only affects Firefox on Windows. Other operating systems are u
Debian
CVE-2022-22753: firefox - A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service tha...
vendor_debian·2022·CVSS 7.1
CVE-2022-22753 [HIGH] CVE-2022-22753: firefox - A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service tha...
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-05: CVE-2022-22753
vendor_mozilla·CVSS 7.1
CVE-2022-22753 [HIGH] Mozilla Foundation Security Advisory 2022-05: CVE-2022-22753
Mozilla Foundation Security Advisory 2022-05
CVE: CVE-2022-22753
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 91.6
Mozilla
Mozilla Foundation Security Advisory 2022-06: CVE-2022-22753
vendor_mozilla·CVSS 7.1
CVE-2022-22753 [HIGH] Mozilla Foundation Security Advisory 2022-06: CVE-2022-22753
Mozilla Foundation Security Advisory 2022-06
CVE: CVE-2022-22753
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.6
Mozilla
Mozilla Foundation Security Advisory 2022-04: CVE-2022-22753
vendor_mozilla·CVSS 7.1
CVE-2022-22753 [HIGH] Mozilla Foundation Security Advisory 2022-04: CVE-2022-22753
Mozilla Foundation Security Advisory 2022-04
CVE: CVE-2022-22753
Product: Firefox
Impact: high
Fixed in: Firefox 97
VulDB
Mozilla Thunderbird up to 91.5 Maintenance Service toctou (Bug 1732435 / EUVD-2022-27896)
vuldb·2026-04-28·CVSS 7.1
CVE-2022-22753 [HIGH] Mozilla Thunderbird up to 91.5 Maintenance Service toctou (Bug 1732435 / EUVD-2022-27896)
A vulnerability, which was classified as very critical, was found in Mozilla Thunderbird up to 91.5. This issue affects some unknown processing of the component Maintenance Service. The manipulation results in time-of-check time-of-use.
This vulnerability is reported as CVE-2022-22753. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
VulDB
Mozilla Firefox up to 96 Maintenance Service toctou (Bug 1732435 / EUVD-2022-27896)
vuldb·2026-04-28·CVSS 7.1
CVE-2022-22753 [HIGH] Mozilla Firefox up to 96 Maintenance Service toctou (Bug 1732435 / EUVD-2022-27896)
A vulnerability was found in Mozilla Firefox up to 96 and classified as very critical. This vulnerability affects unknown code of the component Maintenance Service. The manipulation results in time-of-check time-of-use.
This vulnerability is known as CVE-2022-22753. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-pr6h-wqwg-8wxx: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary director
ghsa_unreviewed·2022-12-22
CVE-2022-22753 [HIGH] CWE-367 GHSA-pr6h-wqwg-8wxx: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary director
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1732435https://www.mozilla.org/security/advisories/mfsa2022-04/https://www.mozilla.org/security/advisories/mfsa2022-05/https://www.mozilla.org/security/advisories/mfsa2022-06/https://bugzilla.mozilla.org/show_bug.cgi?id=1732435https://www.mozilla.org/security/advisories/mfsa2022-04/https://www.mozilla.org/security/advisories/mfsa2022-05/https://www.mozilla.org/security/advisories/mfsa2022-06/
2022-12-22
Published