← Back

CVE-2013-1673

nvd nist
Published: May 16, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD

Description

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."

Affected (5)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Mozilla
Up to 20.0.1
Version 19.0.1
Version 19.0.2
Version 19.0
Version 20.0
Running on/withPlatform Versions
Microsoft
Windows
All versions

Related CWEs

Timeline

No history available yet.