First published: Wed Jun 26 2013(Updated: )
The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=21.0 | |
Mozilla Firefox | =19.0 | |
Mozilla Firefox | =19.0.1 | |
Mozilla Firefox | =19.0.2 | |
Mozilla Firefox | =20.0 | |
Mozilla Firefox | =20.0.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1700 is classified as a high severity vulnerability due to its potential to allow local privilege escalation.
To fix CVE-2013-1700, upgrade Mozilla Firefox to version 22.0 or later.
CVE-2013-1700 affects users of Mozilla Firefox versions 21.0 and earlier on Windows.
CVE-2013-1700 can be exploited by local users through the placement of a Trojan horse executable.
The primary impact of CVE-2013-1700 is local privilege escalation, allowing unauthorized access to system resources.