CVE-2015-0833

Description

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dll.

Risk Information

Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.052

Associated Vulnerability

VulnerabilityOS Platform
Update for SeaMonkey (2.35)Windows
Update for Mozilla Firefox ESR (38.1.0)Windows
Update for Mozilla Firefox ESR (38.1.1)Windows
Update for Mozilla Firefox ESR (38.2)Windows
Update for Mozilla Firefox ESR (38.2.1)Windows
Update for Mozilla Firefox ESR (38.3.0)Windows
Update for Mozilla Firefox ESR (38.4.0)Windows
Update for Mozilla Firefox ESR (38.5.0)Windows
Update for Mozilla Firefox ESR (38.5.1)Windows
Update for Mozilla Firefox ESR (38.5.2)Windows
Update for Mozilla Firefox ESR (38.6.0)Windows
Update for Mozilla Firefox ESR (38.6.1)Windows
Update for Mozilla Firefox ESR (38.7.0)Windows
Vulnerability CVE-2015-0833 are affected in Mozilla Firefox 35.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.10.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.6Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.6.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.7Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.7.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.8Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9.3Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla Firefox (x64) 0.9.rcWindows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.6Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.7Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.8Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla Firefox (x64) 1.0.preview_releaseWindows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.10Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.11Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.12Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.6Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.7Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.8Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.9Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.5Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla Firefox (x64) 1.5.beta1Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla Firefox (x64) 1.5.beta2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.10.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.3Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.5Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.6Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.6.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.7Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.7.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.8Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9.3Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla_Firefox 0.9.rcWindows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.3Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.5Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.6Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.7Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.8Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla_Firefox 1.0.preview_releaseWindows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.10Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.11Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.12Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.3Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.5Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.6Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.7Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.8Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.9Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.3Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.5Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla_Firefox 1.5.beta1Windows
Vulnerabilities CVE-2014-1484,CVE-2014-1501,CVE-2014-1527,CVE-2015-0833 are affected in Mozilla_Firefox 1.5.beta2Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 31.0Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 31.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.4.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 35.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.5Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 31.1.2Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 31.3Windows
Vulnerabilities CVE-2015-0833 are affected in Mozilla Thunderbird 31.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.4.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 35.0.1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-301494Update for SeaMonkey (2.35)
PATCH-302079Update for Mozilla Firefox ESR (38.1.0)
PATCH-302171Update for Mozilla Firefox ESR (38.1.1)
PATCH-302283Update for Mozilla Firefox ESR (38.2)
PATCH-302284Update for Mozilla Firefox ESR (38.2.1)
PATCH-302285Update for Mozilla Firefox ESR (38.3.0)
PATCH-302286Update for Mozilla Firefox ESR (38.4.0)
PATCH-302287Update for Mozilla Firefox ESR (38.5.0)
PATCH-302288Update for Mozilla Firefox ESR (38.5.1)
PATCH-302289Update for Mozilla Firefox ESR (38.5.2)
PATCH-302290Update for Mozilla Firefox ESR (38.6.0)
PATCH-302291Update for Mozilla Firefox ESR (38.6.1)
PATCH-302292Update for Mozilla Firefox ESR (38.7.0)
PATCH-343015Mozilla Firefox (132.0.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234