CVE-2017-7761: Medium severity firefox vulnerability
The Mozilla Maintenance Service helper.exe application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.
Other sources
The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7755
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
- CVE-2017-5470
Frequently Asked Questions
What is the severity of CVE-2017-7761?
CVE-2017-7761 is considered a moderate severity vulnerability.
How do I fix CVE-2017-7761?
To fix CVE-2017-7761, upgrade to Mozilla Firefox version 54 or later and Firefox ESR version 52.3 or later.
What causes CVE-2017-7761?
CVE-2017-7761 is caused by the Mozilla Maintenance Service creating a writable temporary directory that can be exploited by non-privileged users.
Which versions of Firefox are affected by CVE-2017-7761?
CVE-2017-7761 affects Firefox versions up to 54 and Firefox ESR versions up to 52.2.
Is my operating system affected by CVE-2017-7761?
CVE-2017-7761 specifically affects Mozilla Firefox and Firefox ESR running on Microsoft Windows.