| Vulnerability Name: | CVE-2013-1700 (CCN-85272) | ||||||||||||
| Assigned: | 2013-06-25 | ||||||||||||
| Published: | 2013-06-25 | ||||||||||||
| Updated: | 2017-09-19 | ||||||||||||
| Summary: | The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location. | ||||||||||||
| CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2013-1700 Source: CCN Type: SA53953 Mozilla Firefox / Thunderbird Multiple Vulnerabilities Source: CCN Type: SA53970 Mozilla Firefox Multiple Vulnerabilities Source: CCN Type: SA54087 Avant Browser Rendering Engines Multiple Vulnerabilities Source: CCN Type: Avant Browser Web site Avant Browser 2013 build 112, Released 8.19.2013 Source: CONFIRM Type: Vendor Advisory http://www.mozilla.org/security/announce/2013/mfsa2013-62.html Source: CCN Type: BID-60791 Mozilla Firefox CVE-2013-1700 Local Privilege Escalation Vulnerability Source: CONFIRM Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=867056 Source: XF Type: UNKNOWN mozilla-cve20131700-priv-esc(85272) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:17126 Source: CCN Type: MFSA 2013-62 Inaccessible updater can lead to local privilege escalation | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||