CVE-2016-5295Mozilla Firefox vulnerability

CWE-2643 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 76.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox < 50.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified50
NVDmozilla/firefox< 50.0

🔴Vulnerability Details

1
GHSA
GHSA-2h24-5rmg-2c3m: This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozill2022-05-14

📋Vendor Advisories

1
Debian
CVE-2016-5295: firefox - This vulnerability allows an attacker to use the Mozilla Maintenance Service to ...2016