Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-12388
Published: May 5, 2020 / Updated: May 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass sandbox restrictions.
The vulnerability exists due the Firefox content processes did not sufficiently lockdown access control due to improper protection of access tokens. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.
Note, this vulnerability affects Windows versions only.
Affected software
Mozilla Firefox
Slackware Linux
Opensuse
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
How to mitigate CVE-2020-12388
Mozilla Firefox - update to 76.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - addressed in versions 68.8.0-r0, 68.9.0-r0
mozjs68 (Alpine package) - addressed in versions 68.8.0-r0, 68.9.0-r0
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Slackware Linux update for mozilla-firefox
- OpenSUSE Linux update for MozillaFirefox
- Permissions, Privileges, and Access Controls in mozjs68 (Alpine package)
- Permissions, Privileges, and Access Controls in firefox-esr (Alpine package)
- Permissions, Privileges, and Access Controls in firefox (Alpine package)