PT-2012-3674 · Mozilla+2 · Thunderbird+4

James Forshaw

·

Published

2012-06-05

·

Updated

2017-12-29

·

CVE-2012-1943

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 12.0 Thunderbird version 12.0 SeaMonkey version 2.9
Description The issue is related to an untrusted search path vulnerability in the Updater.exe component of the Windows Updater Service. This vulnerability allows local users to gain privileges by using a Trojan horse wsock32.dll file in an application directory.
Recommendations For Mozilla Firefox version 12.0, update to a version that includes a fix for this issue. For Thunderbird version 12.0, update to a version that includes a fix for this issue. For SeaMonkey version 2.9, update to a version that includes a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-1943

Affected Products

Firefox
Seamonkey
Suse
Thunderbird
Windows