CVE-2017-7767 describes a local privilege escalation vulnerability in the Mozilla Maintenance Service affecting Firefox ESR < 52.2 and Firefox < 54 on Windows. An unprivileged local user can exploit this by leveraging the Mozilla Windows Updater to overwrite arbitrary files with junk data, as the updater runs with the Maintenance Service's elevated privileges. This medium severity vulnerability (CVSS 5.5) requires local system access and results in high impact to integrity, but no confidentiality or availability impact. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA KEV, and community discussion and media coverage are minimal, indicating low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 54.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.