An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2018-06-11T21:00:00
Updated: 2024-08-05T16:12:28.506Z
Reserved: 2017-04-12T00:00:00
Link: CVE-2017-7766
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-11T21:29:08.530
Modified: 2024-11-21T03:32:37.200
Link: CVE-2017-7766
Redhat
No data.