PT-2012-3674 · Mozilla+2 · Thunderbird+4
James Forshaw
·
Published
2012-06-05
·
Updated
2017-12-29
·
CVE-2012-1943
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox version 12.0
Thunderbird version 12.0
SeaMonkey version 2.9
Description
The issue is related to an untrusted search path vulnerability in the Updater.exe component of the Windows Updater Service. This vulnerability allows local users to gain privileges by using a Trojan horse wsock32.dll file in an application directory.
Recommendations
For Mozilla Firefox version 12.0, update to a version that includes a fix for this issue.
For Thunderbird version 12.0, update to a version that includes a fix for this issue.
For SeaMonkey version 2.9, update to a version that includes a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Seamonkey
Suse
Thunderbird
Windows