#VU32904 Insecure DLL loading in Mozilla Firefox and Firefox ESR - CVE-2020-15657
Published: July 29, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner from the installation directory. A remote attacker can place a specially crafted .dll file into directory, from which Firefox is being installed, trick the victim into launching the Firefox installer and execute arbitrary code on the system.