When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
2020-01-08T22:15:11.810
2024-11-21T04:31:32.013
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 71.0 | Yes |
Application | mozilla | firefox_esr | < 68.3 | Yes |
Application | mozilla | thunderbird | < 68.3 | Yes |
Operating System | microsoft | windows | - | No |
Operating System | opensuse | leap | 15.1 | Yes |