PT-2019-6230 · Mozilla+2 · Firefox Esr+3
Holger Fuhrmannek
·
Publicado
2019-09-03
·
Atualizado
2024-12-12
·
CVE-2019-11753
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 69
Mozilla Firefox ESR versions prior to 60.9
Mozilla Firefox ESR versions prior to 68.1
Description
The issue is related to the lack of integrity checks in the Mozilla Maintenance Service for Windows, which can be exploited to escalate privileges. This can occur when the Firefox installer allows the browser to be installed in a custom, user-writable location, making it vulnerable to manipulation by unprivileged users or malware. If the Maintenance Service is altered to update this unprotected location and the updated service has been modified, it can run with elevated privileges during the update process. This attack requires local system access and only affects Windows.
Recommendations
For Mozilla Firefox versions prior to 69, update to version 69 or later to resolve the issue.
For Mozilla Firefox ESR versions prior to 60.9, update to version 60.9 or later to resolve the issue.
For Mozilla Firefox ESR versions prior to 68.1, update to version 68.1 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Firefox Esr
Suse