vendor:
Firefox
by:
Glafkos Charalambous
7.5
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: Firefox
Affected Version From: <= 3.6.8
Affected Version To: 3.6.2008
Patch Exists: NO
Related CWE:
CPE: a:mozilla:firefox
Platforms Tested: Windows XP SP3
2010
Firefox <= 3.6.8 DLL Hijacking Exploit [dwmapi.dll]
This exploit allows an attacker to hijack the dwmapi.dll file in Firefox version 3.6.8 or earlier. The vulnerable extensions are .htm, .html, .jtx, and .mfp. By exploiting this vulnerability, an attacker can execute arbitrary code on the victim's system.
Mitigation:
Update Firefox to a version higher than 3.6.8 and avoid opening untrusted files with the vulnerable extensions.