CVE-2017-7755
published 2018-06-11CVE-2017-7755: The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged…
PriorityP433high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.41%
69.6th percentile
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | < 52.2.0 | 52.2.0 |
| mozilla | firefox | < 54.0 | 54.0 |
| mozilla | firefox | >= unspecified < 54 | 54 |
| mozilla | firefox_esr | >= unspecified < 52.2 | 52.2 |
| mozilla | thunderbird | < 52.2.0 | 52.2.0 |
| mozilla | thunderbird | >= unspecified < 52.2 | 52.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3p4h-hgf4-rvgh: The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run
ghsa_unreviewed·2022-05-14
CVE-2017-7755 [HIGH] CWE-426 GHSA-3p4h-hgf4-rvgh: The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Debian
CVE-2017-7755: firefox - The Firefox installer on Windows can be made to load malicious DLL files stored ...
vendor_debian·2017·CVSS 7.8
CVE-2017-7755 [HIGH] CVE-2017-7755: firefox - The Firefox installer on Windows can be made to load malicious DLL files stored ...
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99057http://www.securitytracker.com/id/1038689https://bugzilla.mozilla.org/show_bug.cgi?id=1361326https://www.mozilla.org/security/advisories/mfsa2017-15/https://www.mozilla.org/security/advisories/mfsa2017-16/https://www.mozilla.org/security/advisories/mfsa2017-17/http://www.securityfocus.com/bid/99057http://www.securitytracker.com/id/1038689https://bugzilla.mozilla.org/show_bug.cgi?id=1361326https://www.mozilla.org/security/advisories/mfsa2017-15/https://www.mozilla.org/security/advisories/mfsa2017-16/https://www.mozilla.org/security/advisories/mfsa2017-17/
2018-06-11
Published