First published: Thu May 16 2013(Updated: )
The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=20.0.1 | |
Firefox | =19.0 | |
Firefox | =19.0.1 | |
Firefox | =19.0.2 | |
Firefox | =20.0 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1673 is classified as a moderate severity vulnerability that can allow local users to gain elevated privileges.
To resolve CVE-2013-1673, update your Mozilla Firefox to version 21.0 or later.
CVE-2013-1673 affects Mozilla Firefox versions 20.0 and earlier, including specific versions like 19.0 to 20.0.1.
CVE-2013-1673 can be exploited by local users who have write access to a trusted path.
CVE-2013-1673 involves the Mozilla Updater and the Mozilla Maintenance Service registry entries.