CVE-2017-7761
Status: ModifiedMedium (5.5)—
The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Base score: 5.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.31%
- Percentile among all scored CVEs: 22
- Score date: 10/11/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-276
References
- http://www.securityfocus.com/bid/99057
- http://www.securitytracker.com/id/1038689
- https://bugzilla.mozilla.org/show_bug.cgi?id=1215648
- https://sourceforge.net/p/nsis/bugs/1125/
- https://www.mozilla.org/security/advisories/mfsa2017-15/
- https://www.mozilla.org/security/advisories/mfsa2017-16/
- http://www.securityfocus.com/bid/99057
- http://www.securitytracker.com/id/1038689
- https://bugzilla.mozilla.org/show_bug.cgi?id=1215648
- https://sourceforge.net/p/nsis/bugs/1125/
- https://www.mozilla.org/security/advisories/mfsa2017-15/
- https://www.mozilla.org/security/advisories/mfsa2017-16/
Raw JSON (NVD)
Show
{
"id": "CVE-2017-7761",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@mozilla.org",
"affectedData": [
{
"vendor": "Mozilla",
"product": "Firefox ESR",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "52.2",
"versionType": "custom"
}
]
},
{
"vendor": "Mozilla",
"product": "Firefox",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "54",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-06-11T21:29:08.297",
"references": [
{
"url": "http://www.securityfocus.com/bid/99057",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@mozilla.org"
},
{
"url": "http://www.securitytracker.com/id/1038689",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@mozilla.org"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1215648",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "security@mozilla.org"
},
{
"url": "https://sourceforge.net/p/nsis/bugs/1125/",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "security@mozilla.org"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2017-15/",
"tags": [
"Vendor Advisory"
],
"source": "security@mozilla.org"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2017-16/",
"tags": [
"Vendor Advisory"
],
"source": "security@mozilla.org"
},
{
"url": "http://www.securityfocus.com/bid/99057",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1038689",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1215648",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sourceforge.net/p/nsis/bugs/1125/",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2017-15/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2017-16/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Mozilla Maintenance Service \"helper.exe\" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54."
},
{
"lang": "es",
"value": "La aplicación \"helper.exe\" de Mozilla Maintenance Service crea un directorio temporal escribible por usuarios no privilegiados. Cuando esto se combina con la creación de un junction (un tipo de vínculo simbólico), los archivos protegidos en el directorio objetivo del junction pueden ser eliminados por Mozilla Maintenance Service, el cual tiene acceso privilegiado. Nota: Este ataque requiere acceso local al sistema y solo afecta a Windows. Otros sistemas operativos no se han visto afectados. La vulnerabilidad afecta a Firefox ESR en versiones anteriores a la 52.2 y Firefox en versiones anteriores a la 54."
}
],
"lastModified": "2026-06-17T01:25:08.653",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F5DBE64-6529-4705-869D-4FD030CFADE0",
"versionEndExcluding": "52.2.0"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12FE3109-0EE6-49DC-974A-E522F55B17E1",
"versionEndExcluding": "54.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@mozilla.org"
}