Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-32678 | Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://yandex.com/bugbounty/i/hall-of-fame-browser/ |
|
History
No history.
Status: PUBLISHED
Assigner: yandex
Published:
Updated: 2024-08-03T05:48:37.380Z
Reserved: 2022-03-30T00:00:00.000Z
Link: CVE-2022-28226
No data.
Status : Modified
Published: 2022-06-15T20:15:17.823
Modified: 2024-11-21T06:56:59.303
Link: CVE-2022-28226
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD