cbcvebase.
CVE-2017-5409
published 2018-06-11

CVE-2017-5409: The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter…

PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.36%
28.8th percentile
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
mozillafirefox< 52.052.0
mozillafirefox< 45.8.045.8.0
mozillafirefox>= unspecified < 5252
mozillafirefox_esr>= unspecified < 45.845.8

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.