7.2

CVE-2013-1700

The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version <= 21.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 19.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 19.0.1
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 19.0.2
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 20.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 20.0.1
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.286
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mozilla.org/security/announce/2013/mfsa2013-62.html
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=867056
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17126