Skip to content
COOEY

EXPOSURES › CVE-2022-26485

CVE-2022-26485

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26485 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Firefox use-after-free flaw in XSLT processing allows remote code execution.

A use-after-free vulnerability in Firefox's XSLT parameter processing enables arbitrary code execution, posing a severe risk to systems relying on the browser for web-based operations. DIB organizations must ensure their browsers are patched immediately, as this flaw was actively exploited in the wild and could lead to data breaches or ransomware deployment if unpatched.

Shame score — A critical RCE flaw in a widely used browser was actively exploited in the wild, demonstrating severe negligence in patch management and leaving organizations exposed to remote compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.