Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr6h-wqwg-8wxx

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.
This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.
This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

EPSS

Процентиль: 47%
0.00632
Низкий

7.1 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 3 лет назад

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 7.5
redhat
больше 4 лет назад

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 7.1
nvd
больше 3 лет назад

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 7.1
debian
больше 3 лет назад

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) S ...

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость службы Maintenance (Updater) Service браузера Mozilla Firefox, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 47%
0.00632
Низкий

7.1 High

CVSS3

Дефекты

CWE-367