Improper validation of integrity check value in Mozilla Firefox - CVE-2019-11753

 

Improper validation of integrity check value in Mozilla Firefox - CVE-2019-11753

Published: September 3, 2019


Vulnerability identifier: #VU20822
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11753
CWE-ID: CWE-354
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the Mozilla Maintenance Service does not check integrity of the binary files that were installed into a custom and unprotected folder on the system. A local user can manipulate the Mozilla Maintenance Service to update this unprotected location and escalate privilege on the system.

Note, the vulnerability affects Windows installation only.


Affected software

Mozilla Firefox
Firefox ESR
firefox-esr (Alpine package)

How to mitigate CVE-2019-11753

Install updates from vendor's website.

Mozilla Firefox - update to 69.0
Firefox ESR - addressed in versions 60.9.0, 68.1.0

External References

Related Security Bulletins