6.9
CVSSv2

CVE-2012-1943

Published: 05/06/2012 Updated: 29/12/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 12.0

mozilla thunderbird 12.0

mozilla seamonkey 2.9

Vendor Advisories

Mozilla Foundation Security Advisory 2012-35 Privilege escalation through Mozilla Updater and Windows Updater Service Announced June 5, 2012 Reporter James Forshaw Impact Critical Products Firefox, SeaMonkey, Thunderbird ...