CVE Vulnerabilities

CVE-2014-1520

Improper Privilege Management

Published: Apr 30, 2014 | Modified: Nov 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*29.0 (excluding)
FirefoxMozilla24.0 (including)24.5 (excluding)
FirefoxUbuntulucid*
FirefoxUbuntuupstream*

Potential Mitigations

References