First published: Tue Mar 07 2017(Updated: )
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <52.0 | |
Microsoft Windows | ||
Firefox ESR | <45.8.0 | |
Firefox | <52 | 52 |
Firefox ESR | <45.8 | 45.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5409 has been classified as a high severity vulnerability due to its potential for local file deletion by non-privileged users.
To mitigate CVE-2017-5409, users should update affected Mozilla Firefox products to versions 45.8 or higher for Firefox ESR and 52 or higher for regular Firefox.
CVE-2017-5409 affects users of Mozilla Firefox and Firefox ESR prior to versions 45.8 and 52 respectively, on Windows operating systems.
CVE-2017-5409 cannot be exploited remotely as it requires local system access to successfully execute the attack.
The impacted products include Mozilla Firefox up to version 52 and Mozilla Firefox ESR up to version 45.8.