Unrated severityNVD Advisory· Published Jun 11, 2018· Updated Aug 5, 2024
CVE-2017-7755
CVE-2017-7755
Description
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Affected products
49- osv-coords46 versionspkg:rpm/suse/firefox-gcc5&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/firefox-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/firefox-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/firefox-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/firefox-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/firefox-libffi-gcc5&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/firefox-libffi-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/firefox-libffi-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/firefox-libffi-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/firefox-libffi-gcc5&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20OpenStack%20Cloud%206pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%206pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
< 5.3.1+r233831-7.1+ 45 more
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 5.3.1+r233831-7.1
- (no CPE)range: < 52-24.3.44
- (no CPE)range: < 52-24.3.44
- (no CPE)range: < 52-24.3.44
- (no CPE)range: < 52-24.3.44
- (no CPE)range: < 52-24.3.44
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52-31.1
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-72.5.2
- (no CPE)range: < 52.2.0esr-72.5.2
- (no CPE)range: < 52.2.0esr-72.5.2
- (no CPE)range: < 52.2.0esr-72.5.2
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-72.5.2
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-72.5.2
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 52.2.0esr-108.3
- (no CPE)range: < 3.29.5-47.3.2
- (no CPE)range: < 3.29.5-47.3.2
- (no CPE)range: < 3.29.5-47.3.2
- (no CPE)range: < 3.29.5-47.3.2
- (no CPE)range: < 3.29.5-47.3.2
- (no CPE)range: < 3.29.5-47.3.2
- Range: unspecified
- Range: unspecified
- Mozilla/Firefox ESRv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/99057mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1038689mitrevdb-entryx_refsource_SECTRACK
- bugzilla.mozilla.org/show_bug.cgimitrex_refsource_CONFIRM
- www.mozilla.org/security/advisories/mfsa2017-15/mitrex_refsource_CONFIRM
- www.mozilla.org/security/advisories/mfsa2017-16/mitrex_refsource_CONFIRM
- www.mozilla.org/security/advisories/mfsa2017-17/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.