PT-2022-2932 · Yandex · Yandex Browser

Xi-Tauw

·

Published

2022-03-30

·

Updated

2023-08-08

·

CVE-2022-28226

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yandex Browser versions prior to 22.3.3.801
Description The issue is related to errors in processing temporary files during the update process, which can allow an attacker to elevate their privileges. A local, low-privileged attacker can execute arbitrary code with SYSTEM privileges by manipulating temporary files in a directory with insecure permissions.
Recommendations For versions prior to 22.3.3.801, update to version 22.3.3.801 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary files directory to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2022-03533
CVE-2022-28226

Affected Products

Yandex Browser