Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15663

Опубликовано: 01 окт. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9.3
CVSS3: 8.8

Описание

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, and Firefox ESR < 78.2.

РелизСтатусПримечание
bionic

not-affected

windows only
devel

not-affected

windows only
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

not-affected

windows only
groovy

not-affected

windows only
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

80

Показывать по

РелизСтатусПримечание
bionic

not-affected

Windows only
devel

not-affected

Windows only
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

not-affected

Windows only
groovy

not-affected

Windows only
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

68.11

Показывать по

EPSS

Процентиль: 82%
0.01674
Низкий

9.3 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
больше 5 лет назад

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, and Firefox ESR < 78.2.

CVSS3: 8.8
nvd
больше 5 лет назад

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, and Firefox ESR < 78.2.

CVSS3: 8.8
debian
больше 5 лет назад

If Firefox is installed to a user-writable directory, the Mozilla Main ...

CVSS3: 8.8
github
больше 3 лет назад

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, and Firefox ESR < 78.2.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость службы Maintenance Service браузеров Mozilla Firefox, Mozilla Firefox ESR и почтового клиента Thunderbird для Windows, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями

EPSS

Процентиль: 82%
0.01674
Низкий

9.3 Critical

CVSS2

8.8 High

CVSS3