CVE-2017-7796 is a local file deletion vulnerability affecting Mozilla Firefox on Windows systems, specifically versions prior to 55. The vulnerability arises because the Firefox updater's logging mechanism, when run, deletes an "update.log" file whose path is supplied via the command line. An attacker could potentially manipulate this path in conjunction with another local exploit to delete an unintended file named "update.log". Rated with a CVSS score of 4.7 (Medium), this vulnerability has a local attack vector and high attack complexity, requiring a low-privileged user and no user interaction. The potential impact is limited to high integrity loss (file deletion) with no confidentiality or availability impact. There is no evidence of active exploitation, nor is there any public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 55.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 55CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.