Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-3993Improper Privilege Management in Mozilla Firefox

Severity
9.3CRITICALNVD
EPSS
80.8%
top 0.85%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 10
Latest updateMay 13

Description

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site, related to an "XrayWrapper pollution" issue.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDmozilla/firefox15.0.1+139
NVDmozilla/thunderbird15.0.1+104
NVDmozilla/thunderbird_esr8 versions+7
NVDmozilla/seamonkey2.13+38

🔴Vulnerability Details

2
GHSA
GHSA-3587-g6j7-969g: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 162022-05-13
CVEList
CVE-2012-3993: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 162012-10-10

💥Exploits & PoCs

1
Exploit-DB
Mozilla Firefox 5.0 < 15.0.1 - __exposedProps__ XCS Code Execution (Metasploit)2013-08-06

🔍Detection Rules

1
Suricata
ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt2015-05-08

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2012-10-12
Red Hat
Mozilla: Chrome Object Wrapper (COW) does not disallow acces to privileged functions or properties (MFSA 2012-83)2012-10-09
Ubuntu
Firefox vulnerabilities2012-10-09

💬Community

1
Bugzilla
CVE-2012-3993 CVE-2012-4184 Mozilla: Chrome Object Wrapper (COW) does not disallow acces to privileged functions or properties (MFSA 2012-83)2012-10-06
CVE-2012-3993 — Improper Privilege Management | cvebase