Vulnerability Description
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandex | Yandex Browser | < 22.3.3.801 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://yandex.com/bugbounty/i/hall-of-fame-browser/Vendor Advisory
- https://yandex.com/bugbounty/i/hall-of-fame-browser/Vendor Advisory
FAQ
What is CVE-2022-28226?
CVE-2022-28226 is a vulnerability with a CVSS score of 7.8 (HIGH). Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating tempor...
How severe is CVE-2022-28226?
CVE-2022-28226 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28226?
Check the references section above for vendor advisories and patch information. Affected products include: Yandex Yandex Browser, Microsoft Windows.