3.3
CVSSv2

CVE-2015-4481

Published: 16/08/2015 Updated: 30/10/2018
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 335
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Race condition in the Mozilla Maintenance Service in Mozilla Firefox prior to 40.0 and Firefox ESR 38.x prior to 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox_esr 38.0

mozilla firefox_esr 38.0.1

mozilla firefox_esr 38.0.5

mozilla firefox_esr 38.1.0

opensuse opensuse 13.1

opensuse opensuse 13.2

oracle solaris 11.3

Vendor Advisories

Mozilla Foundation Security Advisory 2015-84 Arbitrary file overwriting through Mozilla Maintenance Service with hard links Announced August 11, 2015 Reporter James Forshaw Impact High Products Firefox, Firefox ESR, SeaMonkey ...

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=427&can=1 Mozilla Maintenance Service: Log File Overwrite Elevation of Privilege Platform: Windows Version: Mozilla Firefox 3805 Class: Elevation of Privilege Summary: The maintenance service creates a log file in a user writable location It’s possible to change ...