CVE-2017-7755: Mozilla Firefox

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Affected products

  • Mozilla Firefox: before 52.2.0 (fixed in 52.2.0); before 54.0 (fixed in 54.0)
  • Mozilla Thunderbird: before 52.2.0 (fixed in 52.2.0)

Published 2018-06-11. Last modified 2026-06-17.