6.9
CVSSv2

CVE-2014-1520

Published: 30/04/2014 Updated: 17/03/2021
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox prior to 29.0 and Firefox ESR 24.x prior to 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox_esr

fedoraproject fedora 19

fedoraproject fedora 20

Vendor Advisories

Mozilla Foundation Security Advisory 2014-35 Privilege escalation through Mozilla Maintenance Service Installer Announced April 29, 2014 Reporter Ash Impact High Products Firefox, Firefox ESR Fixed in ...

Exploits

The fix applied for CVE-2014-1520 does not fix a DLL hijacking issue with Mozilla Firefox's executable installer ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Unholy CRAP: Moziila's executable installers <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: "Stefan Kant ...