CVE-2017-7755 describes a DLL hijacking vulnerability in the Firefox installer on Windows, affecting Firefox versions prior to 54, Firefox ESR prior to 52.2, and Thunderbird prior to 52.2. An attacker can place a malicious DLL in the same directory as the installer, which will then be loaded and executed when the installer is run, potentially leading to privileged execution if the installer is launched with elevated rights. This vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not on the CISA KEV list, it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 54.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 52.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.