First published: Wed Apr 30 2014(Updated: )
maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <29.0 | |
Mozilla Firefox ESR | >=24.0<24.5 | |
Microsoft Windows | ||
Fedoraproject Fedora | =19 | |
Fedoraproject Fedora | =20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1520 has a CVSS score that suggests a significant risk for local privilege escalation.
To remediate CVE-2014-1520, update Mozilla Firefox to version 29.0 or later, or Firefox ESR to version 24.5 or later.
CVE-2014-1520 affects users of Mozilla Firefox versions prior to 29.0 and Firefox ESR versions from 24.0 to 24.5 on Windows platforms.
CVE-2014-1520 is a local privilege escalation vulnerability caused by incorrect handling of a temporary directory.
CVE-2014-1520 cannot be exploited remotely, as it requires local access to the affected system.