CVE-2013-1715

medium

Description

Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.

References

http://www.mozilla.org/security/announce/2013/mfsa2013-74.html

https://bugzilla.mozilla.org/show_bug.cgi?id=883165

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18210

Details

Source: MITRE

Published: 2013-08-07

Updated: 2017-09-19

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM