← Back

CVE-2015-4505

nvd nist
Published: Sep 24, 2015Modified: May 6, 2026

JSON object

Loading...
6.6
Vector
AV:L/AC:L/Au:N/C:N/I:C/A:C
Exploitability: 3.9 / Impact: 9.2
Source: NVD

Description

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.

Affected (8)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 38.0.1
Version 38.0.5
Version 38.0
Version 38.1.0
Version 38.1.1
Version 38.2.0
Version 38.2.1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 40.0.3
Running on/withPlatform Versions
Microsoft
Windows
All versions

Related CWEs

Timeline

No history available yet.