CVE-2016-2826
published 2016-06-13CVE-2016-2826: The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during…
PriorityP434high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.8th percentile
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | <= 46.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-2826: firefox - The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x befo...
vendor_debian·2016·CVSS 7.8
CVE-2016-2826 [HIGH] CVE-2016-2826: firefox - The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x befo...
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
Scope: local
sid: resolved
GHSA
GHSA-f7c8-7wc6-wrv3: The maintenance service in Mozilla Firefox before 47
ghsa_unreviewed·2022-05-17
CVE-2016-2826 [HIGH] GHSA-f7c8-7wc6-wrv3: The maintenance service in Mozilla Firefox before 47
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.mozilla.org/security/announce/2016/mfsa2016-55.htmlhttp://www.securityfocus.com/bid/91075http://www.securitytracker.com/id/1036057https://bugzilla.mozilla.org/show_bug.cgi?id=1237219http://www.mozilla.org/security/announce/2016/mfsa2016-55.htmlhttp://www.securityfocus.com/bid/91075http://www.securitytracker.com/id/1036057https://bugzilla.mozilla.org/show_bug.cgi?id=1237219
2016-06-13
Published