High severity7.8NVD Advisory· Published Dec 22, 2022· Updated Jun 17, 2026
CVE-2022-0517
CVE-2022-0517
Description
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2.7.1+ 1 more
- (no CPE)range: <2.7.1
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- www.mozilla.org/security/advisories/mfsa2022-08/nvdVendor Advisory
News mentions
0No linked articles in our index yet.