The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Sep 20, 2017 | Mar 13, 2017 |
| Freebsd | — | Upgrade seamonkeyUpgrade linux-seamonkeyUpgrade libxulUpgrade thunderbirdUpgrade firefoxUpgrade linux-firefoxUpgrade linux-thunderbirdUpgrade firefox-esr | Mar 8, 2017 | Mar 7, 2017 |
| Mfsa2017 05 | — | Upgrade to Mozilla Firefox version 52.0Upgrade to the latest version of Mozilla Firefox | Mar 8, 2017 | Mar 7, 2017 |
| Mfsa2017 06 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 45.8 | Mar 8, 2017 | Mar 7, 2017 |
| Oracle Solaris | — | Upgrade web/browser/firefox/plugin/firefox-java to version 45.8.0-0.175.3.19.0.2.0 on Solaris 11.3Upgrade web/data/firefox-bookmarks to version 45.8.0-0.175.3.19.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 45.8.0-0.175.3.19.0.2.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations | Mar 18, 2017 | Mar 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub