PT-2019-6230 · Mozilla+2 · Firefox Esr+3

Holger Fuhrmannek

·

Publicado

2019-09-03

·

Atualizado

2024-12-12

·

CVE-2019-11753

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 69 Mozilla Firefox ESR versions prior to 60.9 Mozilla Firefox ESR versions prior to 68.1
Description The issue is related to the lack of integrity checks in the Mozilla Maintenance Service for Windows, which can be exploited to escalate privileges. This can occur when the Firefox installer allows the browser to be installed in a custom, user-writable location, making it vulnerable to manipulation by unprivileged users or malware. If the Maintenance Service is altered to update this unprotected location and the updated service has been modified, it can run with elevated privileges during the update process. This attack requires local system access and only affects Windows.
Recommendations For Mozilla Firefox versions prior to 69, update to version 69 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 60.9, update to version 60.9 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 68.1, update to version 68.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2640
ALT-PU-2019-2644
ALT-PU-2019-2686
ALT-PU-2020-1617
BDU:2022-05799
CVE-2019-11753
MGASA-2019-0267
MGASA-2019-0268
OPENSUSE-SU-2019:2251-1
OPENSUSE-SU-2019:2260-1
OPENSUSE-SU-2019_2251-1
OPENSUSE-SU-2019_2260-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:14173-1
SUSE-SU-2019:14246-1
SUSE-SU-2019:2436-1
SUSE-SU-2019:2545-1
SUSE-SU-2019:2620-1
SUSE-SU-2019_14173-1
SUSE-SU-2019_14246-1

Produtos afetados

Alt Linux
Firefox
Firefox Esr
Suse