6.9

CVE-2013-1712

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update directory or (2) the current working directory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version <= 22.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.1
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.2
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.3
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.4
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.5
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.6
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version17.0.7
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version19.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version19.0.1
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version19.0.2
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version20.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version20.0.1
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaFirefox Version21.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version <= 17.0.7
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0.1
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0.2
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0.3
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0.4
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0.5
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Version17.0.6
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.1
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.2
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.3
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.4
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.5
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.6
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
MozillaThunderbird Esr Version17.0.7
   MicrosoftWindows 7
   MicrosoftWindows 8 Version- Update- Editionx64
   MicrosoftWindows 8 Version- Update- Editionx86
   MicrosoftWindows Server 2008 Versionr2
   MicrosoftWindows Server 2012 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.382
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C