CVE-2017-7766: High severity firefox vulnerability
An attack using manipulation of updater.ini contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.
Other sources
An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7755
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
- CVE-2017-5470
Frequently Asked Questions
What is the severity of CVE-2017-7766?
CVE-2017-7766 is classified as a privilege escalation vulnerability that can lead to arbitrary file execution and deletion.
How do I fix CVE-2017-7766?
To remediate CVE-2017-7766, update Mozilla Firefox to version 54 or later and Firefox ESR to version 52.2 or later.
Who is affected by CVE-2017-7766?
CVE-2017-7766 affects users of Mozilla Firefox versions up to 54 and Firefox ESR versions up to 52.2.
What type of attack is represented by CVE-2017-7766?
CVE-2017-7766 involves an attack leveraging manipulated updater.ini contents to escalate privileges through the Mozilla Maintenance Service.
Is CVE-2017-7766 specific to any operating system?
CVE-2017-7766 primarily affects the Windows operating system when using Mozilla's browsers.