Уязвимость загрузки DLL-файлов из каталога установки в Mozilla Firefox и Thunderbird на операционной системе Windows
Описание
Mozilla Firefox и Thunderbird способны загружать DLL-файлы, предоставленные злоумышленником, из каталога установки. Для этого злоумышленнику необходимо иметь возможность размещать файлы в каталоге установки.
Примечание: Эта проблема затрагивает только операционные системы Windows. Другие операционные системы не подвержены уязвимости.
Затронутые версии ПО
- Firefox ESR до версии 78.1
- Firefox до версии 79
- Thunderbird до версии 78.1
Тип уязвимости
Загрузка DLL-файлов
Ссылки
- Third Party Advisory
- Issue TrackingPermissions RequiredVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Issue TrackingPermissions RequiredVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
7.8 High
CVSS3
6.9 Medium
CVSS2
Дефекты
Связанные уязвимости
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Firefox could be made to load attacker-supplied DLL files from the ins ...
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
EPSS
7.8 High
CVSS3
6.9 Medium
CVSS2