CVE-2014-1520: Fedoraproject Fedora
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
Affected products
- Fedoraproject Fedora: version 19 only; version 20 only
- Mozilla Firefox: before 29.0 (fixed in 29.0); from 24.0, before 24.5 (fixed in 24.5)
Published 2014-04-30. Last modified 2026-06-17.