Vulnerability Name: | CVE-2013-1673 (CCN-84257) | ||||||||||||||||
Assigned: | 2013-05-14 | ||||||||||||||||
Published: | 2013-05-14 | ||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||
Summary: | The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path." | ||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-1673 Source: CCN Type: SA53400 Mozilla Firefox Multiple Vulnerabilities Source: CCN Type: MFSA 2013-45 Mozilla Updater fails to update some Windows Registry entries Source: CONFIRM Type: Vendor Advisory http://www.mozilla.org/security/announce/2013/mfsa2013-45.html Source: CCN Type: BID-59873 Mozilla Firefox CVE-2013-1673 Local Privilege Escalation Vulnerability Source: CONFIRM Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=854088 Source: XF Type: UNKNOWN mozilla-cve20131673-priv-esc(84257) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:17125 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |