First published: Tue Nov 15 2016(Updated: )
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <50 | 50 |
<50 | 50 | |
Mozilla Firefox | <50.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2016-5295 is a vulnerability that allows an attacker to use the Mozilla Maintenance Service to escalate privilege.
CVE-2016-5295 works by having the Mozilla Maintenance Service invoke the Mozilla Updater to run malicious local files.
Yes, CVE-2016-5295 requires local system access.
CVE-2016-5295 has a severity level of medium (4).
To mitigate the impact of CVE-2016-5295, update your Mozilla Firefox to a version higher than 50.