Loading HuntDB...

GHSA-cfrv-hc6m-h3rp

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

Related CVEs

Key Information

GHSA ID
GHSA-cfrv-hc6m-h3rp
Published
May 13, 2022 1:47 AM
Last Modified
May 13, 2022 1:47 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.