[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Privilege escalation vulnerability with Mozilla Maintenance Service in custom Firefox installation location - CVE-2019-11753

ID: oval:org.secpod.oval:def:58335Date: (C)2019-10-11   (M)2024-04-17
Class: VULNERABILITYFamily: windows




Mozilla Firefox 69, Mozilla Firefox ESR 68.1 : The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally.

Platform:
Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Windows Server 2003
Microsoft Windows 8
Microsoft Windows XP
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2012 R2
Microsoft Windows 10
Product:
Mozilla Firefox
Mozilla Firefox ESR
Reference:
CVE-2019-11753
CVE    1
CVE-2019-11753

© SecPod Technologies