← Back to CVEs
CVE-2017-7767
N/ADescription
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
CVE Details
CVSS v3.1 ScoreN/A
Published6/11/2018
Last Modified11/25/2025
Sourcenvd
Honeypot Sightings0
Affected Products
microsoft:windowsmozilla:firefox
Weaknesses (CWE)
CWE-269
References
http://www.securityfocus.com/bid/99057(security@mozilla.org)
http://www.securitytracker.com/id/1038689(security@mozilla.org)
https://bugzilla.mozilla.org/show_bug.cgi?id=1336964(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2017-15/(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2017-16/(security@mozilla.org)
http://www.securityfocus.com/bid/99057(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1038689(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=1336964(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2017-15/(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2017-16/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.