CVE-2014-1520

Description

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

Risk Information

Base Score
8.6
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.039

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 28.0Windows
Multiple vulnerabilities affected in Mozilla Firefox ESR (x64) 24.4Windows
Multiple vulnerabilities affected in Mozilla Firefox ESR 24.4Windows
Multiple vulnerabilities affected in Mozilla_Firefox 28.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 28.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 24.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 28.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 24.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 28.99Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 24.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 24.4Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-310844Mozilla Firefox ESR (x64) (60.9.0)
PATCH-310843Mozilla Firefox ESR (60.9.0)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-343016Mozilla Firefox (x64) (132.0.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234