CVE-2017-7755
Last modified
CVE-2017-7755 is a vulnerability of currently unknown severity. The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 52.2.0 |
| Mozilla | Firefox | < 54.0 |
| Mozilla | Thunderbird | < 52.2.0 |
References
- http://www.securityfocus.com/bid/99057Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038689Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1361326Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-15/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-16/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-17/Vendor Advisory
- http://www.securityfocus.com/bid/99057Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038689Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1361326Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-15/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-16/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-17/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7755?
How severe is CVE-2017-7755?
How do I fix CVE-2017-7755?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7749A use-after-free vulnerability when using an incorrect URL d…
- CVE-2017-7750A use-after-free vulnerability during video control operatio…
- CVE-2017-7751A use-after-free vulnerability with content viewer listeners…
- CVE-2017-7752A use-after-free vulnerability during specific user interact…
- CVE-2017-7753An out-of-bounds read occurs when applying style rules to ps…
- CVE-2017-7754An out-of-bounds read in WebGL with a maliciously crafted "I…
- CVE-2017-7756A use-after-free and use-after-scope vulnerability when logg…
- CVE-2017-7757A use-after-free vulnerability in IndexedDB when one of its …
- CVE-2017-7758An out-of-bounds read vulnerability with the Opus encoder wh…
- CVE-2017-7759Android intent URLs given to Firefox for Android can be used…
- CVE-2017-7760The Mozilla Windows updater modifies some files to be update…
- CVE-2017-7761The Mozilla Maintenance Service "helper.exe" application cre…
Are you affected by CVE-2017-7755?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
