CVE-2017-7761 describes a local privilege escalation vulnerability in the Mozilla Maintenance Service on Windows, affecting Firefox ESR < 52.2 and Firefox < 54. A non-privileged user can create a temporary directory and a symbolic link, allowing the privileged Maintenance Service to delete protected files. This attack requires local system access and has a CVSS score of 5.5 (Medium), indicating a low attack complexity and potential high impact on integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one media article mentioning the Firefox 54 release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 54.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.