CVE-2017-7836

HIGH

Mozilla Firefox < 56.0.2 - Uncontrolled Search Path

Title source: rule

Description

The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 25.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

mozilla/firefox < 56.0.2

Timeline

Published Jun 11, 2018
Tracked Since Feb 18, 2026