Improper validation of integrity check value in Mozilla Firefox - CVE-2019-11753
Published: September 3, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the Mozilla Maintenance Service does not check integrity of the binary files that were installed into a custom and unprotected folder on the system. A local user can manipulate the Mozilla Maintenance Service to update this unprotected location and escalate privilege on the system.
Note, the vulnerability affects Windows installation only.
Affected software
Firefox ESR
firefox-esr (Alpine package)
How to mitigate CVE-2019-11753
Firefox ESR - addressed in versions 60.9.0, 68.1.0