Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-12388

 

Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-12388

Published: May 5, 2020 / Updated: May 29, 2020


Vulnerability identifier: #VU27530
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12388
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass sandbox restrictions.

The vulnerability exists due the Firefox content processes did not sufficiently lockdown access control due to improper protection of access tokens. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.

Note, this vulnerability affects Windows versions only.


Affected software

Firefox ESR
Mozilla Firefox
Slackware Linux
Opensuse
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)

How to mitigate CVE-2020-12388

Install updates from vendor's website.

Firefox ESR - update to 68.8.0
Mozilla Firefox - update to 76.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - addressed in versions 68.8.0-r0, 68.9.0-r0
mozjs68 (Alpine package) - addressed in versions 68.8.0-r0, 68.9.0-r0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins