CVE-2017-7766 is a local privilege escalation vulnerability affecting Mozilla Firefox and Firefox ESR on Windows. An attacker with local system access can manipulate the updater.ini file and leverage the Mozilla Maintenance Service to achieve arbitrary file execution and deletion with privileged access. This vulnerability has a CVSS score of 7.8 (High), indicating a significant impact on confidentiality, integrity, and availability. While no public exploit code is available, the vulnerability has received some community discussion and media coverage, though it is not actively exploited or on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 54.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.