CVE-2016-2826 describes a privilege escalation vulnerability in the maintenance service of Mozilla Firefox and Firefox ESR on Windows. Specifically, versions prior to 47.0 and 45.x before 45.2, respectively, are affected. The vulnerability allows a local attacker to modify extracted files during updater execution, potentially leading to privilege escalation through a Trojan horse file. Rated with a CVSS score of 7.8 (HIGH), this vulnerability has a low attack complexity and requires local user privileges, but can result in high impacts to confidentiality, integrity, and availability. Despite its severity, the EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation (KEV: No), and no public exploit intelligence such as Metasploit, Nuclei, or ExploitDB entries are available. Community discussion and media coverage are minimal, with only one mention and one article identified, indicating limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
45.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.0:*:*:*:*:*:*:* | ||
45.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.1:*:*:*:*:*:*:* | ||
<= 46.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.