CVE-2013-1673
Published May 16, 2013
Last updated 7 years ago
Overview
- Description
- The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."
- Source
- security@mozilla.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1246AD3-6704-42B1-89AE-E9DD64D3D7D7", "versionEndIncluding": "20.0.1" }, { "criteria": "cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06FF9DFE-491D-4260-8A49-07FD342B9412" }, { "criteria": "cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE09D089-7F48-466B-B03A-C64152A12615" }, { "criteria": "cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "653D73DA-21C0-4C3F-9269-5A6D5C5B1E34" }, { "criteria": "cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "804A0ACE-EB28-413D-93F4-E849FEA01390" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256" } ], "operator": "OR" } ], "operator": "AND" } ]