CVE-2022-36314

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
22/12/2022
Last modified:
15/04/2025

Description

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 103.0 (excluding)
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* 102.1 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 102.1 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*