Mozilla Security Updates – 24 August 2022

Mozilla has released security updates to fix vulnerabilities in Firefox , Firefox ESR and Thunderbird. The remote attacker could exploit these vulnerabilities to gain access, escalate privileges, and bypass security controls.

Sample of The Addressed Vulnerabilities:

  1. Mozilla Firefox security bypass (CVE-2022-38473):
    • CVSS: 8.8
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Consequences: Security Bypass

  2. Mozilla Firefox code execution (CVE-2022-38478):
    • CVSS: 8.8
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Consequences: Gain Access
Vulnerabilities
  • CVE-2022-38473
  • CVE-2022-38478
  • CVE-2022-38472
  • CVE-2022-38476
  • CVE-2022-38477
  • CVE-2022-38475
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Security Advisor

References