An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-seamonkeyUpgrade thunderbirdUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-firefoxUpgrade libxulUpgrade seamonkeyUpgrade firefox-esr | Aug 8, 2017 | Aug 8, 2017 |
| Mfsa2017 18 | — | Upgrade to Mozilla Firefox version 55.0 | Aug 9, 2017 | Aug 8, 2017 |
| Mfsa2017 19 | — | Upgrade to Mozilla Firefox ESR version 52.3 | Aug 9, 2017 | Aug 8, 2017 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 52.3 | Aug 21, 2017 | Aug 18, 2017 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 52.3.0-0.175.3.24.0.4.0 on Solaris 11.3Upgrade mail/thunderbird to version 52.3.0-0.175.3.24.0.4.0 on Solaris 11.3 | Sep 19, 2017 | Sep 19, 2017 |
| Suse | — | Upgrade mozillathunderbird-translations-otherUpgrade mozillafirefoxUpgrade mozillafirefox-translations-otherUpgrade mozillathunderbird-translations-commonUpgrade MozillaFirefox-translationsUpgrade mozillafirefox-develUpgrade mozillathunderbirdUpgrade mozillafirefox-translations-commonUpgrade MozillaThunderbird-buildsymbolsUpgrade mozillafirefox-branding-sledUpgrade MozillaThunderbird-devel | Aug 12, 2017 | Aug 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub