7.8
CVSSv3

CVE-2016-2826

Published: 13/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The maintenance service in Mozilla Firefox prior to 47.0 and Firefox ESR 45.x prior to 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox_esr 45.1.1

mozilla firefox_esr 45.1.0

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2016-55 File overwrite and privilege escalation through Mozilla Windows updater Announced June 7, 2016 Reporter Frédéric Hoguin Impact High Products Firefox, Firefox ESR Fixed in ...