The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. <br>*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade libxulUpgrade linux-firefoxUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefox-esrUpgrade linux-thunderbirdUpgrade waterfox | Sep 4, 2019 | Sep 3, 2019 |
| Mfsa2019 25 | — | Upgrade to Mozilla Firefox version 69.0Upgrade to the latest version of Mozilla Firefox | Sep 4, 2019 | Sep 3, 2019 |
| Mfsa2019 26 | — | Upgrade to Mozilla Firefox ESR version 68.1Upgrade to the latest version of Mozilla Firefox | Sep 4, 2019 | Sep 3, 2019 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.12.0-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Sep 27, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 27, 2019 |
| Suse | — | Upgrade firefox-gtk3-dataUpgrade MozillaFirefox-branding-SLEDUpgrade libfreebl3Upgrade mozilla-nspr-develUpgrade firefox-gtk3-immodules-tigrignaUpgrade firefox-gtk3-immodule-vietnameseUpgrade firefox-libharfbuzz0Upgrade firefox-libffi7Upgrade mozillafirefox-branding-sleUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade libsoftokn3-32bitUpgrade firefox-gtk3-immodule-thaiUpgrade firefox-glib2-langUpgrade firefox-gtk3-branding-upstreamUpgrade firefox-gtk3-immodule-inuktitutUpgrade MozillaFirefox-develUpgrade mozilla-nsprUpgrade libfirefox-gobject-2_0-0Upgrade firefox-gtk3-immodule-multipressUpgrade mozilla-nss-develUpgrade firefox-gio-branding-upstreamUpgrade mozilla-nspr-32bitUpgrade firefox-libgdk_pixbuf-2_0-0Upgrade libfirefox-gthread-2_0-0Upgrade libfirefox-gmodule-2_0-0Upgrade firefox-gtk3-toolsUpgrade firefox-gdk-pixbuf-query-loadersUpgrade firefox-libcairo2Upgrade firefox-libffi4Upgrade firefox-libcairo-gobject2Upgrade firefox-gtk3-immodule-amharicUpgrade libfreebl3-32bitUpgrade libsoftokn3Upgrade firefox-gdk-pixbuf-thumbnailerUpgrade libfirefox-gio-2_0-0Upgrade mozilla-nssUpgrade firefox-gtk3-immodule-ximUpgrade mozillafirefox-branding-upstreamUpgrade firefox-glib2-toolsUpgrade mozillafirefox-buildsymbolsUpgrade libfirefox-glib-2_0-0Upgrade firefox-gdk-pixbuf-langUpgrade firefox-libpango-1_0-0Upgrade mozilla-nss-certsUpgrade firefox-libatk-1_0-0Upgrade firefox-gtk3-langUpgrade mozilla-nss-32bitUpgrade MozillaFirefox-translations-otherUpgrade firefox-libgtk-3-0Upgrade mozilla-nss-certs-32bitUpgrade mozilla-nss-toolsUpgrade firefox-atk-lang | Oct 8, 2019 | Sep 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub