CVE-2022-0517
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileg
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.
HIGH · CVSS 7.8
EPSS 0.00041
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0