CVE-2017-7755 PUBLISHED CVSS 6.800000190734863 MEDIUM

The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

EPSS 0.77% · 73.3th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
0.77%
73.3th percentile

Affected Products

VendorProductVersions
MozillaFirefox ESRunspecified
MozillaThunderbirdunspecified
MozillaFirefoxunspecified
mozillafirefox0, 0
mozillathunderbird0

Timeline

References

Open in Interactive Console →