---
title: "CVE-2017-7804\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-7804?format=md
keywords: index, follow
---

# CVE-2017-7804

Publication date 11 June 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2017-7804?format=md#impact-score)

Toggle side navigation

## Description

The destructor function for the "WindowsDllDetourPatcher" class can be
re-purposed by malicious code in concert with another vulnerability to
write arbitrary data to an attacker controlled location in memory. This can
be used to bypass existing memory protections in this situation. Note: This
attack only affects Windows operating systems. Other operating systems are
not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR <
52.3, and Firefox < 55.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2017-7804?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 17.04 zesty | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| thunderbird | 17.04 zesty | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [chrisccoulson](https://launchpad.net/~chrisccoulson)

Windows only

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7804)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-7804)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-7804)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-7804)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2017-7804>
