vulnerability

MFSA2016-55 Firefox: File overwrite and privilege escalation through Mozilla Windows updater (CVE-2016-2826)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 7, 2016
Added
Jun 8, 2016
Modified
Nov 27, 2024

Description

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.

Solutions

mozilla-firefox-esr-upgrade-45_2mozilla-firefox-upgrade-47_0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.