The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade firefox-esr | Aug 22, 2024 | Aug 1, 2023 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Feb 21, 2024 | Aug 1, 2023 |
| Mfsa2023 29 | — | Upgrade to Mozilla Firefox version 116.0Upgrade to the latest version of Mozilla Firefox | Aug 2, 2023 | Aug 1, 2023 |
| Mfsa2023 31 | — | Upgrade to Mozilla Firefox ESR version 115.1Upgrade to the latest version of Mozilla Firefox | Aug 2, 2023 | Aug 1, 2023 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 115.1 | Aug 3, 2023 | Aug 1, 2023 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbirdUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-common | Aug 3, 2023 | Aug 1, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub