---
title: "CVE-2013-1672\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1672?format=md
keywords: index, follow
---

# CVE-2013-1672

Publication date 16 May 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR
17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x
before 17.0.6 on Windows allows local users to bypass integrity
verification and gain privileges via vectors involving junctions.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-1672?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Ignored end of life |
| thunderbird | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [chrisccoulson](https://launchpad.net/~chrisccoulson)

Affects the Mozilla Maintenance Service on Windows only

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1672)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1672)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1672)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1672)

### Other references

* <http://www.mozilla.org/security/announce/2013/mfsa2013-44.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-1672>
