Vulnerabilities > CVE-2022-28226 - Exposure of Resource to Wrong Sphere vulnerability in Yandex Browser

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
yandex
CWE-668

Summary

Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.

Vulnerable Configurations

Part Description Count
Application
Yandex
120
OS
Microsoft
1

Common Weakness Enumeration (CWE)