Rewterz
Rewterz Threat Advisory – Multiple Apache Gobblin and ActiveMQ Artemis Vulnerabilities
February 25, 2022
Rewterz
Rewterz Threat Advisory – CVE-2022-20650 – Cisco NX-OS Software NX-API Vulnerability
February 25, 2022

Rewterz Threat Advisory – CVE-2022-0517 – Mozilla VPN Vulnerability

Severity

High

Analysis Summary

CVE-2022-0517

Mozilla VPN could allow a local authenticated attacker to gain elevated privileges on the system, caused by an uncontrolled OpenSSL search path flaw. By using a special-crafted OpenSSL configuration, an authenticated attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

Impact

  • Privilege Escalation

Indicators of Compromise

CVE

  • CVE-2022-0517

Affected Vendors

Mozilla

Affected Products

  • Mozilla VPN 2.7.0

Remediation

Refer to Mozilla Foundation Security Advisory for patch, upgrade, or suggested workaround information.

https://www.mozilla.org/en-US/security/advisories/mfsa2022-08/