cbcvebase.
CVE-2017-7755
published 2018-06-11

CVE-2017-7755: The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged…

PriorityP433high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.41%
69.6th percentile
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
mozillafirefox< 52.2.052.2.0
mozillafirefox< 54.054.0
mozillafirefox>= unspecified < 5454
mozillafirefox_esr>= unspecified < 52.252.2
mozillathunderbird< 52.2.052.2.0
mozillathunderbird>= unspecified < 52.252.2

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.