The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privilege escalation by manipulating the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Conclusion & alert: CVE-2017-7760 is rated High Exploit Risk (60.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.12%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2023-03-07 | 0.95% | 0.12% | -0.83% |
| 2 | 2022-02-04 | 12.62% | 0.95% | -11.67% |
| 3 | 2021-04-14 | — | 12.62% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.0 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 4.6 | 2.0 | MEDIUM |
|
3.9 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2017-7760 unimportant priority: Debian including 2 source packages (firefox, firefox-esr), 6 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 6. | https://security-tracker.debian.org/tracker/CVE-2017-7760 |
suse
|
high | CVE-2017-7760 severity important: SUSE including 42 source package names (MozillaFirefox, MozillaFirefox-102.11.0-150200.152.87.1, …), 79 product×package rows across 25 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (25 product lines)): Fixed 45, Known Not Affected 34. | https://www.suse.com/security/cve/CVE-2017-7760/ |
ubuntu
|
medium | CVE-2017-7760 medium priority: Ubuntu including 1 source packages (firefox), 5 status rows across 5 suites (trusty, upstream, xenial, yakkety, zesty): not-affected 3, DNE 1, released 1. | https://ubuntu.com/security/CVE-2017-7760 |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99057 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1038689 | Third Party Advisory VDB Entry |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1348645 | Exploit Issue Tracking Patch Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2017-15/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2017-16/ | Vendor Advisory |