CVE-2013-1672
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via…
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mozilla/firefox · mozilla/thunderbird · mozilla/thunderbird esr
- Source
- security@mozilla.org
References
- http://www.mozilla.org/security/announce/2013/mfsa2013-44.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=850492
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16915
- http://www.mozilla.org/security/announce/2013/mfsa2013-44.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=850492
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16915
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.