CVE-2013-1712

Description

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update directory or (2) the current working directory.

Risk Information

Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.166

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 22.0Windows
Multiple vulnerabilities affected in Mozilla Firefox ESR (x64) 17.0.7Windows
Multiple vulnerabilities affected in Mozilla Firefox ESR 17.0.7Windows
Multiple vulnerabilities affected in Mozilla Thunderbird 17.0.7Windows
Multiple vulnerabilities affected in Mozilla Thunderbird ESR 17.0.7Windows
Multiple vulnerabilities affected in Mozilla_Firefox 22.0Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0.2Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0.3Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0.2Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0.3Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0.5Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 19.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 19.0.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 20.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 20.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 19.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 19.0.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 20.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 20.0.1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-310844Mozilla Firefox ESR (x64) (60.9.0)
PATCH-310843Mozilla Firefox ESR (60.9.0)
PATCH-315938Mozilla Thunderbird (68.12.0)
PATCH-343015Mozilla Firefox (132.0.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234