An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade firefox-esrUpgrade libxulUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade firefoxUpgrade thunderbirdUpgrade linux-thunderbird | Aug 8, 2017 | Aug 8, 2017 |
| Mfsa2017 18 | — | Upgrade to Mozilla Firefox version 55.0 | Aug 9, 2017 | Aug 8, 2017 |
| Mfsa2017 19 | — | Upgrade to Mozilla Firefox ESR version 52.3 | Aug 9, 2017 | Aug 8, 2017 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 52.3 | Aug 21, 2017 | Aug 18, 2017 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 52.3.0-0.175.3.24.0.4.0 on Solaris 11.3Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 52.3.0-0.175.3.24.0.4.0 on Solaris 11.3 | Sep 19, 2017 | Sep 19, 2017 |
| Suse | — | Upgrade MozillaThunderbird-develUpgrade MozillaThunderbird-buildsymbolsUpgrade mozillafirefox-branding-sledUpgrade mozillafirefox-translations-commonUpgrade mozillathunderbirdUpgrade mozillafirefox-translations-otherUpgrade MozillaFirefox-translationsUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-otherUpgrade mozillafirefoxUpgrade mozillafirefox-devel | Aug 12, 2017 | Aug 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub