An error in the WindowsDllDetourPatcher where a RWX (Read/Write/Execute) 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 55.0 (excluding) |
Firefox_esr | Mozilla | * | 52.3.0 (excluding) |
Thunderbird | Mozilla | * | 52.3.0 (excluding) |
Firefox | Ubuntu | upstream | * |
Thunderbird | Ubuntu | upstream | * |