CVE-2015-4481 is a race condition vulnerability in the Mozilla Maintenance Service, affecting Mozilla Firefox on Windows, including Firefox ESR. This flaw allows a local attacker to achieve arbitrary file write and privilege escalation by manipulating hard links to log files during an update process. The vulnerability has a CVSS score of 3.3, indicating low attack complexity and local access, with potential for partial integrity and availability impact. While not listed on CISA's KEV catalog and with no recorded active exploitation, a proof-of-concept exploit is available on ExploitDB, though it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 39.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
38.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:* | ||
38.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:* | ||
38.0.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:* | ||
38.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:N/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.