9.3
CVSSv2

CVE-2020-15663

Published: 01/10/2020 Updated: 12/07/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, and Firefox ESR < 78.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla thunderbird

mozilla firefox esr

Vendor Advisories

Mozilla Foundation Security Advisory 2020-38 Security Vulnerabilities fixed in Firefox ESR 782 Announced August 25, 2020 Impact high Products Firefox ESR Fixed in Firefox ESR 782 ...
Mozilla Foundation Security Advisory 2020-37 Security Vulnerabilities fixed in Firefox ESR 6812 Announced August 25, 2020 Impact high Products Firefox ESR Fixed in Firefox ESR 6812 ...
Mozilla Foundation Security Advisory 2020-40 Security Vulnerabilities fixed in Thunderbird 6812 Announced August 25, 2020 Impact high Products Thunderbird Fixed in Thunderbird 6812 ...
Mozilla Foundation Security Advisory 2020-41 Security Vulnerabilities fixed in Thunderbird 782 Announced August 25, 2020 Impact high Products Thunderbird Fixed in Thunderbird 782 ...
Mozilla Foundation Security Advisory 2020-36 Security Vulnerabilities fixed in Firefox 80 Announced August 25, 2020 Impact high Products Firefox Fixed in Firefox 80 ...