Vulnerability Name: | CVE-2013-1672 (CCN-84256) | ||||||||||||||||
Assigned: | 2013-05-14 | ||||||||||||||||
Published: | 2013-05-14 | ||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||
Summary: | The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions. | ||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-1672 Source: CCN Type: SA53400 Mozilla Firefox Multiple Vulnerabilities Source: CCN Type: SA53410 Mozilla Firefox ESR Multiple Vulnerabilities Source: CCN Type: SA53443 Mozilla Thunderbird Multiple Vulnerabilities Source: CCN Type: MFSA 2013-44 Local privilege escalation through Mozilla Maintenance Service Source: CONFIRM Type: Vendor Advisory http://www.mozilla.org/security/announce/2013/mfsa2013-44.html Source: CCN Type: BID-59872 Mozilla Firefox/Thunderbird CVE-2013-1672 Local Privilege Escalation Vulnerability Source: CONFIRM Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=850492 Source: XF Type: UNKNOWN mozilla-cve20131672-priv-esc(84256) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:16915 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |