CVE-2015-4481
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file…
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- mozilla/firefox · opensuse/opensuse · oracle/solaris
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-84.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securitytracker.com/id/1033247
- http://www.securitytracker.com/id/1033372
- https://bugzilla.mozilla.org/show_bug.cgi?id=1171518Issue Tracking
- https://security.gentoo.org/glsa/201605-06
- https://www.exploit-db.com/exploits/37925/
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html
- http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-84.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securitytracker.com/id/1033247
- http://www.securitytracker.com/id/1033372
- https://bugzilla.mozilla.org/show_bug.cgi?id=1171518Issue Tracking
- https://security.gentoo.org/glsa/201605-06
- https://www.exploit-db.com/exploits/37925/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.