Mozilla Thunderbird CVE-2013-0799 Buffer Overflow Vulnerability

description-logoDescription

Security researcher Frdric Hoguin discovered that the Mozilla Maintenance Service on Windows was vulnerable to a buffer overflow. This system is used to update software without invoking the User Account Control (UAC) prompt. The Mozilla Maintenance Service is configured to allow unprivileged users to start it with arbitrary arguments. By manipulating the data passed in these arguments, an attacker can execute arbitrary code with the system privileges used by the service. This issue requires local file system access to be exploitable.

affected-products-logoAffected Applications

Thunderbird

CVE References

CVE-2013-0799