Loading HuntDB...

GHSA-2h24-5rmg-2c3m

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox < 50.

Related CVEs

Key Information

GHSA ID
GHSA-2h24-5rmg-2c3m
Published
May 14, 2022 3:12 AM
Last Modified
May 14, 2022 3:12 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.