Vulnerability Description
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandex | Yandex Browser | < 22.3.3.684 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://yandex.com/bugbounty/i/hall-of-fame-browser/Vendor Advisory
- https://yandex.com/bugbounty/i/hall-of-fame-browser/Vendor Advisory
FAQ
What is CVE-2022-28225?
CVE-2022-28225 is a vulnerability with a CVSS score of 7.8 (HIGH). Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlin...
How severe is CVE-2022-28225?
CVE-2022-28225 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28225?
Check the references section above for vendor advisories and patch information. Affected products include: Yandex Yandex Browser, Microsoft Windows.