CVE-2017-7767: Medium severity firefox vulnerability
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7755
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
- CVE-2017-5470
Frequently Asked Questions
What is the severity of CVE-2017-7767?
CVE-2017-7767 has a medium severity rating as it allows unprivileged users to overwrite arbitrary files.
How do I fix CVE-2017-7767?
To fix CVE-2017-7767, upgrade to Firefox ESR version 52.3 or later, or Firefox version 54.0 or later.
Which versions of Firefox are affected by CVE-2017-7767?
CVE-2017-7767 affects Firefox ESR up to version 52.2 and Firefox up to version 54.
Is CVE-2017-7767 a remote attack vulnerability?
No, CVE-2017-7767 requires local system access to exploit the vulnerability.
What platforms are vulnerable to CVE-2017-7767?
CVE-2017-7767 only affects the Windows platform.