CVE Vulnerabilities

CVE-2014-1520

Improper Privilege Management

Published: Apr 30, 2014 | Modified: Mar 17, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 29.0 (excluding)
Firefox_esr Mozilla 24.0 (including) 24.5 (excluding)
Firefox Ubuntu lucid *
Firefox Ubuntu upstream *

Potential Mitigations

References