The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2018-06-11T21:00:00
Updated: 2024-08-05T16:12:28.505Z
Reserved: 2017-04-12T00:00:00
Link: CVE-2017-7755
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-11T21:29:07.967
Modified: 2024-11-21T03:32:35.740
Link: CVE-2017-7755
Redhat
No data.