Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206. Per: http://cwe.mitre.org/data/definitions/426.html
CWE-426 Untrusted Search Path
Publication date: Wed, 07 Aug 2013 06:55:00 +0000