CVE-2022-26485highunder attackCWE-416

CVE-2022-26485: high-severity vulnerability in Mozilla Firefox

Published · Updated

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 14%
from disclosure to weapon40 days
Published on NVDDec 22
1st PoC+40d
CISA KEVMar 7
exploitation probability
14%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products (8 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 8
no_fix_planned: Out of support scope
Fixed
10 products (118 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream EUS (v.8.4) · Red Hat Enterprise Linux AppStream EUS (v. 8.2) · Red Hat Enterprise Linux AppStream E4S (v. 8.1) · Red Hat Enterprise Linux Server (v. 7) · and others 5
Not affected
1 product (5 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9
Action required by CISAfederal deadline: 2022-03-21

Apply updates per vendor instructions.

In short

A flaw in XSLT parameter handling allowed attackers to exploit a use-after-free vulnerability, potentially crashing the browser or executing malicious code. This bug affected multiple Firefox products and was actively exploited in real attacks.

Technical detail

Use-after-free vulnerability (CWE-416) in XSLT parameter processing where improper memory management during parameter removal could be leveraged for arbitrary code execution. Remote attack vector requiring user interaction (opening malicious content); impacts Firefox, Firefox ESR, Firefox Android, Thunderbird, and Focus versions prior to specified patches.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.