First published: Wed Aug 29 2012(Updated: )
Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Microsoft Windows Operating System | ||
Any of | ||
Firefox | <=14.0 | |
Firefox | =1.0 | |
Firefox | =1.0-preview_release | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Firefox | =1.0.5 | |
Firefox | =1.0.6 | |
Firefox | =1.0.7 | |
Firefox | =1.0.8 | |
Firefox | =1.4.1 | |
Firefox | =1.5 | |
Firefox | =1.5-beta1 | |
Firefox | =1.5-beta2 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.6 | |
Firefox | =1.5.0.7 | |
Firefox | =1.5.0.8 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.0.12 | |
Firefox | =1.5.1 | |
Firefox | =1.5.2 | |
Firefox | =1.5.3 | |
Firefox | =1.5.4 | |
Firefox | =1.5.5 | |
Firefox | =1.5.6 | |
Firefox | =1.5.7 | |
Firefox | =1.5.8 | |
Firefox | =1.8 | |
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.2 | |
Firefox | =2.0.0.3 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.6 | |
Firefox | =2.0.0.7 | |
Firefox | =2.0.0.8 | |
Firefox | =2.0.0.9 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0.0.11 | |
Firefox | =2.0.0.12 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.14 | |
Firefox | =2.0.0.15 | |
Firefox | =2.0.0.16 | |
Firefox | =2.0.0.17 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0.0.19 | |
Firefox | =2.0.0.20 | |
Firefox | =3.0 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0.3 | |
Firefox | =3.0.4 | |
Firefox | =3.0.5 | |
Firefox | =3.0.6 | |
Firefox | =3.0.7 | |
Firefox | =3.0.8 | |
Firefox | =3.0.9 | |
Firefox | =3.0.10 | |
Firefox | =3.0.11 | |
Firefox | =3.0.12 | |
Firefox | =3.0.13 | |
Firefox | =3.0.14 | |
Firefox | =3.0.15 | |
Firefox | =3.0.16 | |
Firefox | =3.0.17 | |
Firefox | =3.5 | |
Firefox | =3.5.1 | |
Firefox | =3.5.2 | |
Firefox | =3.5.3 | |
Firefox | =3.5.4 | |
Firefox | =3.5.5 | |
Firefox | =3.5.6 | |
Firefox | =3.5.7 | |
Firefox | =3.5.8 | |
Firefox | =3.5.9 | |
Firefox | =3.5.10 | |
Firefox | =3.5.11 | |
Firefox | =3.5.12 | |
Firefox | =3.5.13 | |
Firefox | =3.5.14 | |
Firefox | =3.5.15 | |
Firefox | =3.6 | |
Firefox | =3.6.2 | |
Firefox | =3.6.3 | |
Firefox | =3.6.4 | |
Firefox | =3.6.6 | |
Firefox | =3.6.7 | |
Firefox | =3.6.8 | |
Firefox | =3.6.9 | |
Firefox | =3.6.10 | |
Firefox | =3.6.11 | |
Firefox | =3.6.12 | |
Firefox | =3.6.13 | |
Firefox | =3.6.14 | |
Firefox | =3.6.15 | |
Firefox | =3.6.16 | |
Firefox | =3.6.17 | |
Firefox | =3.6.18 | |
Firefox | =3.6.19 | |
Firefox | =3.6.20 | |
Firefox | =3.6.21 | |
Firefox | =3.6.22 | |
Firefox | =3.6.23 | |
Firefox | =3.6.24 | |
Firefox | =3.6.25 | |
Firefox | =4.0 | |
Firefox | =4.0-beta1 | |
Firefox | =4.0-beta10 | |
Firefox | =4.0-beta11 | |
Firefox | =4.0-beta12 | |
Firefox | =4.0-beta2 | |
Firefox | =4.0-beta3 | |
Firefox | =4.0-beta4 | |
Firefox | =4.0-beta5 | |
Firefox | =4.0-beta6 | |
Firefox | =4.0-beta7 | |
Firefox | =4.0-beta8 | |
Firefox | =4.0-beta9 | |
Firefox | =4.0.1 | |
Firefox | =5.0 | |
Firefox | =5.0.1 | |
Firefox | =6.0 | |
Firefox | =6.0.1 | |
Firefox | =6.0.2 | |
Firefox | =7.0 | |
Firefox | =7.0.1 | |
Firefox | =8.0 | |
Firefox | =8.0.1 | |
Firefox | =9.0 | |
Firefox | =9.0.1 | |
Firefox | =10.0 | |
Firefox | =10.0.1 | |
Firefox | =10.0.2 | |
Firefox | =11.0 | |
Firefox | =12.0 | |
Firefox | =12.0-beta6 | |
Firefox | =13.0 | |
All of | ||
Any of | ||
Firefox | =10.0 | |
Firefox | =10.0.1 | |
Firefox | =10.0.2 | |
Firefox | =10.0.3 | |
Firefox | =10.0.4 | |
Firefox | =10.0.5 | |
Firefox | =10.0.6 | |
Microsoft Windows Operating System | ||
All of | ||
Any of | ||
Thunderbird | <=14.0 | |
Thunderbird | =1.0 | |
Thunderbird | =1.0.1 | |
Thunderbird | =1.0.2 | |
Thunderbird | =1.0.3 | |
Thunderbird | =1.0.4 | |
Thunderbird | =1.0.5 | |
Thunderbird | =1.0.5-beta | |
Thunderbird | =1.0.6 | |
Thunderbird | =1.0.7 | |
Thunderbird | =1.0.8 | |
Thunderbird | =1.5 | |
Thunderbird | =1.5-beta2 | |
Thunderbird | =1.5.0.1 | |
Thunderbird | =1.5.0.2 | |
Thunderbird | =1.5.0.3 | |
Thunderbird | =1.5.0.4 | |
Thunderbird | =1.5.0.5 | |
Thunderbird | =1.5.0.6 | |
Thunderbird | =1.5.0.7 | |
Thunderbird | =1.5.0.8 | |
Thunderbird | =1.5.0.9 | |
Thunderbird | =1.5.0.10 | |
Thunderbird | =1.5.0.11 | |
Thunderbird | =1.5.0.12 | |
Thunderbird | =1.5.0.13 | |
Thunderbird | =1.5.0.14 | |
Thunderbird | =1.5.1 | |
Thunderbird | =1.5.2 | |
Thunderbird | =1.7.1 | |
Thunderbird | =1.7.3 | |
Thunderbird | =2.0 | |
Thunderbird | =2.0.0.0 | |
Thunderbird | =2.0.0.1 | |
Thunderbird | =2.0.0.2 | |
Thunderbird | =2.0.0.3 | |
Thunderbird | =2.0.0.4 | |
Thunderbird | =2.0.0.5 | |
Thunderbird | =2.0.0.6 | |
Thunderbird | =2.0.0.7 | |
Thunderbird | =2.0.0.8 | |
Thunderbird | =2.0.0.9 | |
Thunderbird | =2.0.0.11 | |
Thunderbird | =2.0.0.12 | |
Thunderbird | =2.0.0.13 | |
Thunderbird | =2.0.0.14 | |
Thunderbird | =2.0.0.15 | |
Thunderbird | =2.0.0.16 | |
Thunderbird | =2.0.0.17 | |
Thunderbird | =2.0.0.18 | |
Thunderbird | =2.0.0.19 | |
Thunderbird | =2.0.0.20 | |
Thunderbird | =2.0.0.21 | |
Thunderbird | =2.0.0.22 | |
Thunderbird | =2.0.0.23 | |
Thunderbird | =3.0 | |
Thunderbird | =3.0.1 | |
Thunderbird | =3.0.2 | |
Thunderbird | =3.0.3 | |
Thunderbird | =3.0.4 | |
Thunderbird | =3.0.5 | |
Thunderbird | =3.0.6 | |
Thunderbird | =3.0.7 | |
Thunderbird | =3.0.8 | |
Thunderbird | =3.0.9 | |
Thunderbird | =3.0.10 | |
Thunderbird | =3.0.11 | |
Thunderbird | =3.1 | |
Thunderbird | =3.1.1 | |
Thunderbird | =3.1.2 | |
Thunderbird | =3.1.3 | |
Thunderbird | =3.1.4 | |
Thunderbird | =3.1.5 | |
Thunderbird | =3.1.6 | |
Thunderbird | =3.1.7 | |
Thunderbird | =3.1.8 | |
Thunderbird | =3.1.9 | |
Thunderbird | =3.1.10 | |
Thunderbird | =3.1.11 | |
Thunderbird | =3.1.12 | |
Thunderbird | =3.1.13 | |
Thunderbird | =3.1.14 | |
Thunderbird | =3.1.15 | |
Thunderbird | =3.1.16 | |
Thunderbird | =3.1.17 | |
Thunderbird | =3.1.18 | |
Thunderbird | =3.1.19 | |
Thunderbird | =5.0 | |
Thunderbird | =6.0 | |
Thunderbird | =6.0.1 | |
Thunderbird | =6.0.2 | |
Thunderbird | =7.0 | |
Thunderbird | =7.0.1 | |
Thunderbird | =8.0 | |
Thunderbird | =9.0 | |
Thunderbird | =9.0.1 | |
Thunderbird | =10.0 | |
Thunderbird | =10.0.1 | |
Thunderbird | =10.0.2 | |
Thunderbird | =10.0.3 | |
Thunderbird | =10.0.4 | |
Thunderbird | =11.0 | |
Thunderbird | =12.0 | |
Thunderbird | =13.0 | |
Microsoft Windows Operating System | ||
All of | ||
Any of | ||
Mozilla Thunderbird | =10.0 | |
Mozilla Thunderbird | =10.0.1 | |
Mozilla Thunderbird | =10.0.2 | |
Mozilla Thunderbird | =10.0.3 | |
Mozilla Thunderbird | =10.0.4 | |
Mozilla Thunderbird | =10.0.5 | |
Mozilla Thunderbird | =10.0.6 | |
Microsoft Windows Operating System | ||
Microsoft Windows Operating System | ||
Firefox | <=14.0 | |
Firefox | =1.0 | |
Firefox | =1.0-preview_release | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Firefox | =1.0.5 | |
Firefox | =1.0.6 | |
Firefox | =1.0.7 | |
Firefox | =1.0.8 | |
Firefox | =1.4.1 | |
Firefox | =1.5 | |
Firefox | =1.5-beta1 | |
Firefox | =1.5-beta2 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.6 | |
Firefox | =1.5.0.7 | |
Firefox | =1.5.0.8 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.0.12 | |
Firefox | =1.5.1 | |
Firefox | =1.5.2 | |
Firefox | =1.5.3 | |
Firefox | =1.5.4 | |
Firefox | =1.5.5 | |
Firefox | =1.5.6 | |
Firefox | =1.5.7 | |
Firefox | =1.5.8 | |
Firefox | =1.8 | |
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.2 | |
Firefox | =2.0.0.3 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.6 | |
Firefox | =2.0.0.7 | |
Firefox | =2.0.0.8 | |
Firefox | =2.0.0.9 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0.0.11 | |
Firefox | =2.0.0.12 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.14 | |
Firefox | =2.0.0.15 | |
Firefox | =2.0.0.16 | |
Firefox | =2.0.0.17 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0.0.19 | |
Firefox | =2.0.0.20 | |
Firefox | =3.0 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0.3 | |
Firefox | =3.0.4 | |
Firefox | =3.0.5 | |
Firefox | =3.0.6 | |
Firefox | =3.0.7 | |
Firefox | =3.0.8 | |
Firefox | =3.0.9 | |
Firefox | =3.0.10 | |
Firefox | =3.0.11 | |
Firefox | =3.0.12 | |
Firefox | =3.0.13 | |
Firefox | =3.0.14 | |
Firefox | =3.0.15 | |
Firefox | =3.0.16 | |
Firefox | =3.0.17 | |
Firefox | =3.5 | |
Firefox | =3.5.1 | |
Firefox | =3.5.2 | |
Firefox | =3.5.3 | |
Firefox | =3.5.4 | |
Firefox | =3.5.5 | |
Firefox | =3.5.6 | |
Firefox | =3.5.7 | |
Firefox | =3.5.8 | |
Firefox | =3.5.9 | |
Firefox | =3.5.10 | |
Firefox | =3.5.11 | |
Firefox | =3.5.12 | |
Firefox | =3.5.13 | |
Firefox | =3.5.14 | |
Firefox | =3.5.15 | |
Firefox | =3.6 | |
Firefox | =3.6.2 | |
Firefox | =3.6.3 | |
Firefox | =3.6.4 | |
Firefox | =3.6.6 | |
Firefox | =3.6.7 | |
Firefox | =3.6.8 | |
Firefox | =3.6.9 | |
Firefox | =3.6.10 | |
Firefox | =3.6.11 | |
Firefox | =3.6.12 | |
Firefox | =3.6.13 | |
Firefox | =3.6.14 | |
Firefox | =3.6.15 | |
Firefox | =3.6.16 | |
Firefox | =3.6.17 | |
Firefox | =3.6.18 | |
Firefox | =3.6.19 | |
Firefox | =3.6.20 | |
Firefox | =3.6.21 | |
Firefox | =3.6.22 | |
Firefox | =3.6.23 | |
Firefox | =3.6.24 | |
Firefox | =3.6.25 | |
Firefox | =4.0 | |
Firefox | =4.0-beta1 | |
Firefox | =4.0-beta10 | |
Firefox | =4.0-beta11 | |
Firefox | =4.0-beta12 | |
Firefox | =4.0-beta2 | |
Firefox | =4.0-beta3 | |
Firefox | =4.0-beta4 | |
Firefox | =4.0-beta5 | |
Firefox | =4.0-beta6 | |
Firefox | =4.0-beta7 | |
Firefox | =4.0-beta8 | |
Firefox | =4.0-beta9 | |
Firefox | =4.0.1 | |
Firefox | =5.0 | |
Firefox | =5.0.1 | |
Firefox | =6.0 | |
Firefox | =6.0.1 | |
Firefox | =6.0.2 | |
Firefox | =7.0 | |
Firefox | =7.0.1 | |
Firefox | =8.0 | |
Firefox | =8.0.1 | |
Firefox | =9.0 | |
Firefox | =9.0.1 | |
Firefox | =10.0 | |
Firefox | =10.0.1 | |
Firefox | =10.0.2 | |
Firefox | =11.0 | |
Firefox | =12.0 | |
Firefox | =12.0-beta6 | |
Firefox | =13.0 | |
Firefox ESR | =10.0 | |
Firefox ESR | =10.0.1 | |
Firefox ESR | =10.0.2 | |
Firefox ESR | =10.0.3 | |
Firefox ESR | =10.0.4 | |
Firefox ESR | =10.0.5 | |
Firefox ESR | =10.0.6 | |
Thunderbird | <=14.0 | |
Thunderbird | =1.0 | |
Thunderbird | =1.0.1 | |
Thunderbird | =1.0.2 | |
Thunderbird | =1.0.3 | |
Thunderbird | =1.0.4 | |
Thunderbird | =1.0.5 | |
Thunderbird | =1.0.5-beta | |
Thunderbird | =1.0.6 | |
Thunderbird | =1.0.7 | |
Thunderbird | =1.0.8 | |
Thunderbird | =1.5 | |
Thunderbird | =1.5-beta2 | |
Thunderbird | =1.5.0.1 | |
Thunderbird | =1.5.0.2 | |
Thunderbird | =1.5.0.3 | |
Thunderbird | =1.5.0.4 | |
Thunderbird | =1.5.0.5 | |
Thunderbird | =1.5.0.6 | |
Thunderbird | =1.5.0.7 | |
Thunderbird | =1.5.0.8 | |
Thunderbird | =1.5.0.9 | |
Thunderbird | =1.5.0.10 | |
Thunderbird | =1.5.0.11 | |
Thunderbird | =1.5.0.12 | |
Thunderbird | =1.5.0.13 | |
Thunderbird | =1.5.0.14 | |
Thunderbird | =1.5.1 | |
Thunderbird | =1.5.2 | |
Thunderbird | =1.7.1 | |
Thunderbird | =1.7.3 | |
Thunderbird | =2.0 | |
Thunderbird | =2.0.0.0 | |
Thunderbird | =2.0.0.1 | |
Thunderbird | =2.0.0.2 | |
Thunderbird | =2.0.0.3 | |
Thunderbird | =2.0.0.4 | |
Thunderbird | =2.0.0.5 | |
Thunderbird | =2.0.0.6 | |
Thunderbird | =2.0.0.7 | |
Thunderbird | =2.0.0.8 | |
Thunderbird | =2.0.0.9 | |
Thunderbird | =2.0.0.11 | |
Thunderbird | =2.0.0.12 | |
Thunderbird | =2.0.0.13 | |
Thunderbird | =2.0.0.14 | |
Thunderbird | =2.0.0.15 | |
Thunderbird | =2.0.0.16 | |
Thunderbird | =2.0.0.17 | |
Thunderbird | =2.0.0.18 | |
Thunderbird | =2.0.0.19 | |
Thunderbird | =2.0.0.20 | |
Thunderbird | =2.0.0.21 | |
Thunderbird | =2.0.0.22 | |
Thunderbird | =2.0.0.23 | |
Thunderbird | =3.0 | |
Thunderbird | =3.0.1 | |
Thunderbird | =3.0.2 | |
Thunderbird | =3.0.3 | |
Thunderbird | =3.0.4 | |
Thunderbird | =3.0.5 | |
Thunderbird | =3.0.6 | |
Thunderbird | =3.0.7 | |
Thunderbird | =3.0.8 | |
Thunderbird | =3.0.9 | |
Thunderbird | =3.0.10 | |
Thunderbird | =3.0.11 | |
Thunderbird | =3.1 | |
Thunderbird | =3.1.1 | |
Thunderbird | =3.1.2 | |
Thunderbird | =3.1.3 | |
Thunderbird | =3.1.4 | |
Thunderbird | =3.1.5 | |
Thunderbird | =3.1.6 | |
Thunderbird | =3.1.7 | |
Thunderbird | =3.1.8 | |
Thunderbird | =3.1.9 | |
Thunderbird | =3.1.10 | |
Thunderbird | =3.1.11 | |
Thunderbird | =3.1.12 | |
Thunderbird | =3.1.13 | |
Thunderbird | =3.1.14 | |
Thunderbird | =3.1.15 | |
Thunderbird | =3.1.16 | |
Thunderbird | =3.1.17 | |
Thunderbird | =3.1.18 | |
Thunderbird | =3.1.19 | |
Thunderbird | =5.0 | |
Thunderbird | =6.0 | |
Thunderbird | =6.0.1 | |
Thunderbird | =6.0.2 | |
Thunderbird | =7.0 | |
Thunderbird | =7.0.1 | |
Thunderbird | =8.0 | |
Thunderbird | =9.0 | |
Thunderbird | =9.0.1 | |
Thunderbird | =10.0 | |
Thunderbird | =10.0.1 | |
Thunderbird | =10.0.2 | |
Thunderbird | =10.0.3 | |
Thunderbird | =10.0.4 | |
Thunderbird | =11.0 | |
Thunderbird | =12.0 | |
Thunderbird | =13.0 | |
Mozilla Thunderbird | =10.0 | |
Mozilla Thunderbird | =10.0.1 | |
Mozilla Thunderbird | =10.0.2 | |
Mozilla Thunderbird | =10.0.3 | |
Mozilla Thunderbird | =10.0.4 | |
Mozilla Thunderbird | =10.0.5 | |
Mozilla Thunderbird | =10.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3974 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2012-3974, update Mozilla Firefox to version 15.0 or later, or upgrade to the corresponding latest version of Thunderbird.
Firefox versions prior to 15.0 are affected by CVE-2012-3974, including all versions from 1.0 to 14.0.
Yes, Thunderbird versions prior to 15.0, including versions from 1.0 to 14.0, are impacted by CVE-2012-3974.
CVE-2012-3974 is an untrusted search path vulnerability that allows local users to gain elevated privileges.