maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 29.0 (excluding) |
Firefox_esr | Mozilla | 24.0 (including) | 24.5 (excluding) |
Firefox | Ubuntu | lucid | * |
Firefox | Ubuntu | upstream | * |