CVE Vulnerabilities

CVE-2015-4505

Published: Sep 24, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.6 MEDIUM
AV:L/AC:L/Au:N/C:N/I:C/A:C
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla38.0 (including)38.0 (including)
FirefoxMozilla38.0.1 (including)38.0.1 (including)
FirefoxMozilla38.0.5 (including)38.0.5 (including)
FirefoxMozilla38.1.0 (including)38.1.0 (including)
FirefoxMozilla38.1.1 (including)38.1.1 (including)
FirefoxMozilla38.2.0 (including)38.2.0 (including)
FirefoxMozilla38.2.1 (including)38.2.1 (including)
FirefoxUbuntuupstream*

References