CVE-2016-2826: High severity microsoft windows operating system vulnerability
Published Jun 13, 2016
·Updated
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
Affected Software
9 affected components
All of the following
Microsoft Windows
Any of the following
Mozilla Firefox=45.1.0
Mozilla Firefox=45.1.1
All of the following
Microsoft Windows
Mozilla Firefox<=46.0.1
Microsoft Windows
Mozilla Firefox ESR=45.1.0
Mozilla Firefox ESR=45.1.1
Mozilla Firefox<=46.0.1
Event History
Jun 13, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2826?
CVE-2016-2826 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2016-2826?
To fix CVE-2016-2826, update Mozilla Firefox to version 47.0 or later.
3
Who is affected by CVE-2016-2826?
CVE-2016-2826 affects users of Mozilla Firefox and Firefox ESR prior to version 47.0 and 45.2 respectively on Windows.
4
What does CVE-2016-2826 exploit?
CVE-2016-2826 exploits a weakness in the maintenance service that does not prevent MAR extracted-file modification during updater execution.
5
Can CVE-2016-2826 allow privilege escalation?
Yes, CVE-2016-2826 can potentially allow local users to gain privileges via a Trojan horse file.