CVE-2016-2826

Description

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.053

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox (47.0)Windows
Update for Mozilla Firefox x64 (47.0)Windows
Update for Mozilla Firefox (47.0.1)Windows
Update for Mozilla Firefox x64 (47.0.1)Windows
Update for Mozilla Firefox ESR (45.2.0)Windows
Vulnerabilities CVE-2016-2824,CVE-2016-2826 are affected in Mozilla Firefox (x64) 45.1.0Windows
Vulnerabilities CVE-2016-2824,CVE-2016-2826 are affected in Mozilla Firefox (x64) 45.1.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 46.0.1Windows
Vulnerabilities CVE-2016-2824,CVE-2016-2826 are affected in Mozilla_Firefox 45.1.0Windows
Vulnerabilities CVE-2016-2824,CVE-2016-2826 are affected in Mozilla_Firefox 45.1.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 46.0.1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-302212Update for Mozilla Firefox x64 (47.0)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-302214Update for Mozilla Firefox x64 (47.0.1)
PATCH-302297Update for Mozilla Firefox ESR (45.2.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234