Rapid7 Vulnerability & Exploit Database

MFSA2021-19 Thunderbird: Security Vulnerabilities fixed in Thunderbird 78.10.1 (CVE-2021-29951)

Back to Search

MFSA2021-19 Thunderbird: Security Vulnerabilities fixed in Thunderbird 78.10.1 (CVE-2021-29951)

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
05/04/2021
Created
05/06/2021
Added
05/05/2021
Modified
07/02/2021

Description

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.

Solution(s)

  • mozilla-thunderbird-upgrade-78_10_1

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;