CVE-2015-2720 PUBLISHED CVSS 4.400000095367432 MEDIUM

The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathname for updater.exe corresponds to the application directory, which might allow local users to gain privileges via a Trojan horse file.

EPSS 0.08% · 22.7th percentile

Risk Scores

CVSS v2.0
4.400000095367432
EPSS Score
0.08%
22.7th percentile

Affected Products

VendorProductVersions
n/an/an/a
mozillafirefox0

Timeline

References

Open in Interactive Console →