6.9 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
6.1 Medium
AI Score
Confidence
Low
0.0004 Low
EPSS
Percentile
14.2%
Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.
lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html
lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html
www.mozilla.org/security/announce/2012/mfsa2012-67.html
www.securityfocus.com/bid/55312
www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
bugzilla.mozilla.org/show_bug.cgi?id=770478
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16692