The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade firefoxUpgrade linux-firefoxUpgrade seamonkey | Dec 10, 2025 | May 15, 2013 |
| Mfsa2013 44 | — | Upgrade to Mozilla Firefox version 21.0Upgrade to Mozilla Firefox ESR version 17.0.6Upgrade to the latest version of Mozilla Firefox | May 18, 2013 | May 16, 2013 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird ESR version 17.0.6Upgrade to Mozilla Thunderbird version 17.0.6Upgrade to the latest version of Mozilla Thunderbird | May 18, 2013 | May 16, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub