Loading HuntDB...

GHSA-w9c7-gp5q-hh44

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

Related CVEs

Key Information

GHSA ID
GHSA-w9c7-gp5q-hh44
Published
May 13, 2022 1:47 AM
Last Modified
May 13, 2022 1:47 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.