6.9
CVSSv2

CVE-2012-4206

Published: 21/11/2012 Updated: 19/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in the installer in Mozilla Firefox prior to 17.0 and Firefox ESR 10.x prior to 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 16.0

mozilla firefox 16.0.1

mozilla firefox 15.0

mozilla firefox 12.0

mozilla firefox 11.0

mozilla firefox 8.0

mozilla firefox 7.0.1

mozilla firefox 4.0

mozilla firefox 3.0.13

mozilla firefox 3.0.1

mozilla firefox 3.6.20

mozilla firefox 3.6

mozilla firefox 3.6.11

mozilla firefox 3.5.14

mozilla firefox 3.6.10

mozilla firefox 3.6.9

mozilla firefox 3.6.15

mozilla firefox 3.6.7

mozilla firefox 3.0.6

mozilla firefox 3.5.2

mozilla firefox 3.5.4

mozilla firefox 3.5.5

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 2.0.0.1

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 1.5

mozilla firefox 1.0.8

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.12

mozilla firefox 1.5.2

mozilla firefox 15.0.1

mozilla firefox 14.0.1

mozilla firefox 10.0.2

mozilla firefox 10.0

mozilla firefox 7.0

mozilla firefox 6.0

mozilla firefox 3.0.11

mozilla firefox 3.0

mozilla firefox 3.6.21

mozilla firefox 3.6.22

mozilla firefox 3.5.12

mozilla firefox 3.0.3

mozilla firefox 3.6.13

mozilla firefox 3.5.7

mozilla firefox 3.6.16

mozilla firefox 3.6.14

mozilla firefox 3.0.8

mozilla firefox 3.6.17

mozilla firefox 3.5.6

mozilla firefox 3.0.2

mozilla firefox 3.5

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.6

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 1.4.1

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 0.10

mozilla firefox 0.8

mozilla firefox 0.6.1

mozilla firefox 0.7

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 0.9.2

mozilla firefox 0.9

mozilla firefox 0.1

mozilla firefox 0.2

mozilla firefox 14.0

mozilla firefox 13.0

mozilla firefox 10.0.1

mozilla firefox 9.0.1

mozilla firefox 6.0.2

mozilla firefox 6.0.1

mozilla firefox 4.0.1

mozilla firefox 3.0.17

mozilla firefox 3.0.16

mozilla firefox 3.0.15

mozilla firefox 3.6.2

mozilla firefox 3.6.25

mozilla firefox 3.5.13

mozilla firefox 3.0.5

mozilla firefox 3.6.19

mozilla firefox 3.6.12

mozilla firefox 3.6.8

mozilla firefox 3.5.11

mozilla firefox 3.0.7

mozilla firefox 3.0.9

mozilla firefox 3.0.4

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.4

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.10

mozilla firefox 1.5.3

mozilla firefox 1.8

mozilla firefox 0.10.1

mozilla firefox 0.9.1

mozilla firefox 0.7.1

mozilla firefox 0.3

mozilla firefox

mozilla firefox 13.0.1

mozilla firefox 9.0

mozilla firefox 8.0.1

mozilla firefox 5.0

mozilla firefox 5.0.1

mozilla firefox 3.0.14

mozilla firefox 3.0.10

mozilla firefox 3.0.12

mozilla firefox 3.6.4

mozilla firefox 3.5.10

mozilla firefox 3.6.24

mozilla firefox 3.6.3

mozilla firefox 3.6.23

mozilla firefox 3.5.1

mozilla firefox 3.6.18

mozilla firefox 3.6.6

mozilla firefox 3.5.8

mozilla firefox 3.5.15

mozilla firefox 3.5.3

mozilla firefox 3.5.9

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.2

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 0.9.3

mozilla firefox 0.4

mozilla firefox 0.5

mozilla firefox 0.6

mozilla firefox_esr 10.0.3

mozilla firefox_esr 10.0.4

mozilla firefox_esr 10.0.1

mozilla firefox_esr 10.0.2

mozilla firefox_esr 10.0.6

mozilla firefox_esr 10.0.8

mozilla firefox_esr 10.0.10

mozilla firefox_esr 10.0.9

mozilla firefox_esr 10.0.7

mozilla firefox_esr 10.0.5

mozilla firefox_esr 10.0

Vendor Advisories

Mozilla Foundation Security Advisory 2012-98 Firefox installer DLL hijacking Announced November 20, 2012 Reporter Robert Kugler Impact High Products Firefox, Firefox ESR Fixed in F ...

Exploits

JRSoft InnoSetup executable installers suffer from a DLL hijacking vulnerability ...