suse · CVE-2017-7760

Quick triage

Priority: high Published: 2021-05-30 13:55:15 UTC Updated: 2026-04-18 09:07:11 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-7760 severity important: SUSE including 42 source package names (MozillaFirefox, MozillaFirefox-102.11.0-150200.152.87.1, …), 79 product×package rows across 25 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (25 product lines)): Fixed 45, Known Not Affected 34.

Description:

The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privilege escalation by manipulating the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

cvelogic Threat Intelligence