vulnerability
MFSA2016-55 Firefox: File overwrite and privilege escalation through Mozilla Windows updater (CVE-2016-2826)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Jun 7, 2016 | Jun 8, 2016 | Nov 27, 2024 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 7, 2016
Added
Jun 8, 2016
Modified
Nov 27, 2024
Description
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
Solutions
mozilla-firefox-esr-upgrade-45_2mozilla-firefox-upgrade-47_0
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.