Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 22 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:* | cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:* | 
| Vendors & Products | Mozilla firefox Esr | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mozilla
Published: 2015-08-16T01:00:00
Updated: 2024-08-06T06:18:11.089Z
Reserved: 2015-06-10T00:00:00
Link: CVE-2015-4481
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2015-08-16T01:59:08.877
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-4481
 Redhat
                        Redhat
                    No data.