CVE-2015-4481
Summary
| CVE | CVE-2015-4481 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-16 01:59:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | All | All | All | All |
| Application | Mozilla | Firefox | 38.0 | All | All | All |
| Application | Mozilla | Firefox | 38.0.1 | All | All | All |
| Application | Mozilla | Firefox | 38.0.5 | All | All | All |
| Application | Mozilla | Firefox | 38.1.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
| Operating System | Oracle | Solaris | 11.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, Bypass Security Restrictions, and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Mozilla - Maintenance Service Log File Overwrite Privilege Escalation - Windows local Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| [security-announce] openSUSE-SU-2015:1389-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Mozilla Thunderbird Multiple Flaws Let Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Mozilla Products: Multiple vulnerabilities (GLSA 201605-06) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [security-announce] openSUSE-SU-2015:1390-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| 1171518 – (CVE-2015-4481) [Win] Privileged update processes writing to user writable locations can overwrite non-user writable locations using hard links | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking |
| Arbitrary file overwriting through Mozilla Maintenance Service with hard links — Mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| openSUSE-SU-2015:1454-1: moderate: Security update for MozillaThunderbir | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2015:1453-1: moderate: Security update for MozillaThunderbir | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Solaris Bulletin - April 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.