PT-2019-6230 · Mozilla+2 · Firefox Esr+3

Holger Fuhrmannek

·

Published

2019-09-03

·

Updated

2024-12-12

·

CVE-2019-11753

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 69 Mozilla Firefox ESR versions prior to 60.9 Mozilla Firefox ESR versions prior to 68.1
Description The issue is related to the lack of integrity checks in the Mozilla Maintenance Service for Windows, which can be exploited to escalate privileges. This can occur when the Firefox installer allows the browser to be installed in a custom, user-writable location, making it vulnerable to manipulation by unprivileged users or malware. If the Maintenance Service is altered to update this unprotected location and the updated service has been modified, it can run with elevated privileges during the update process. This attack requires local system access and only affects Windows.
Recommendations For Mozilla Firefox versions prior to 69, update to version 69 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 60.9, update to version 60.9 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 68.1, update to version 68.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2640
ALT-PU-2019-2644
ALT-PU-2019-2686
ALT-PU-2020-1617
BDU:2022-05799
CVE-2019-11753
MGASA-2019-0267
MGASA-2019-0268
OPENSUSE-SU-2019:2251-1
OPENSUSE-SU-2019:2260-1
OPENSUSE-SU-2019_2251-1
OPENSUSE-SU-2019_2260-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:14173-1
SUSE-SU-2019:14246-1
SUSE-SU-2019:2436-1
SUSE-SU-2019:2545-1
SUSE-SU-2019:2620-1
SUSE-SU-2019_14173-1
SUSE-SU-2019_14246-1

Affected Products

Alt Linux
Firefox
Firefox Esr
Suse