A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade librewolf | Aug 22, 2024 | Dec 22, 2022 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Feb 22, 2022 | Feb 21, 2022 |
| Mfsa2022 04 | — | Upgrade to Mozilla Firefox version 97.0Upgrade to the latest version of Mozilla Firefox | Feb 9, 2022 | Feb 8, 2022 |
| Mfsa2022 05 | — | Upgrade to Mozilla Firefox ESR version 91.6Upgrade to the latest version of Mozilla Firefox | Feb 9, 2022 | Feb 8, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.6Upgrade to the latest version of Mozilla Thunderbird | Feb 17, 2022 | Feb 8, 2022 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade mozillafirefox-branding-upstream | Feb 24, 2022 | Feb 23, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub