CVE-2014-1520
published 2014-04-30CVE-2014-1520: maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users…
PriorityP417medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.1th percentile
maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | firefox | < 29.0 | 29.0 |
| mozilla | firefox | >= 24.0 < 24.5 | 24.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
Privilege escalation via shfolder.dll due to unsafe temp directory created by 7-zip extractors
bugzilla·2016-04-30·CVSS 6.9
[MEDIUM] Privilege escalation via shfolder.dll due to unsafe temp directory created by 7-zip extractors
Privilege escalation via shfolder.dll due to unsafe temp directory created by 7-zip extractors
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:38.0) Gecko/20100101 Firefox/38.0
Build ID: 20160420141331
Steps to reproduce:
0. download "Firefox Setup 38.8.0esr.exe" or "Firefox Setup 46.0.exe";
1. save attached shfolder.cmd, shfolder.dll and shfolder.exe in arbitrary directory;
2. run shfolder.cmd;
3. execute "Firefox Setup 38.8.0esr.exe" or "Firefox Setup 46.0.exe" and answer UAC prompt.
Actual results:
Rogue executables "shfolder.dll" and "shfolder.exe" are executed with administrative privileges.
Expected results:
No UNSAFE subdirectory "7z*.tmp" must be used/created.
See https://cwe.mitre.org/data/definitions/379.html for this well-known and well-documented beginner's error!
Also se
Bugzilla
Privilege escalation via maintenanceservice_installer.exe due to unsafe temp directory created by 7-zip extractors
bugzilla·2016-04-30·CVSS 6.9
[MEDIUM] Privilege escalation via maintenanceservice_installer.exe due to unsafe temp directory created by 7-zip extractors
Privilege escalation via maintenanceservice_installer.exe due to unsafe temp directory created by 7-zip extractors
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:38.0) Gecko/20100101 Firefox/38.0
Build ID: 20160420141331
Steps to reproduce:
0. download "Firefox Setup 38.8.0esr.exe" or "Firefox Setup 46.0.exe";
1. execute "Firefox Setup 38.8.0esr.exe" or "Firefox Setup 46.0.exe";
2. answer UAC prompt and wait until first dialog is displayed;
3.a start Windows Explorer,
3.b navigate to %TEMP%,
3.c find subdirectory "7z*.tmp" created by Firefox*Setup*.exe and open it,
3.d open subdirectory "core",
3.e overwrite "maintenanceservice_installer.exe" with arbitrary trojan/virus/...
4. continue with Firefox installation, accepting all defaults
Actual results:
Rogue executable "maintenanceservice
Bugzilla
Privilege escalation via maintenanceservice.exe due to unsafe temp directory created by 7-zip extractors
bugzilla·2016-04-30·CVSS 6.9
[MEDIUM] Privilege escalation via maintenanceservice.exe due to unsafe temp directory created by 7-zip extractors
Privilege escalation via maintenanceservice.exe due to unsafe temp directory created by 7-zip extractors
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:38.0) Gecko/20100101 Firefox/38.0
Build ID: 20160420141331
Steps to reproduce:
0. download "Firefox Setup 38.8.0esr.exe" or "Firefox Setup 46.0.exe";
1. execute "Firefox Setup 38.8.0esr.exe" or "Firefox Setup 46.0.exe";
2. answer UAC prompt and wait until first dialog is displayed;
3.a start Windows Explorer,
3.b navigate to %TEMP%,
3.c find subdirectory "7z*.tmp" created by Firefox*Setup*.exe and open it,
3.d open subdirectory "core",
3.e overwrite "maintenanceservice.exe" with arbitrary trojan/virus/...
4. continue with Firefox installation, accepting all defaults
Actual results:
Rogue executable "maintenanceservice" (written by unpriv
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.htmlhttp://packetstormsecurity.com/files/161696/Mozilla-Arbitrary-Code-Execution-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2021/Mar/14http://secunia.com/advisories/59866http://www.mozilla.org/security/announce/2014/mfsa2014-35.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030163https://bugzilla.mozilla.org/show_bug.cgi?id=961676https://security.gentoo.org/glsa/201504-01http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.htmlhttp://packetstormsecurity.com/files/161696/Mozilla-Arbitrary-Code-Execution-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2021/Mar/14http://secunia.com/advisories/59866http://www.mozilla.org/security/announce/2014/mfsa2014-35.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030163https://bugzilla.mozilla.org/show_bug.cgi?id=961676https://security.gentoo.org/glsa/201504-01
2014-04-30
Published