Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-12389
Published: May 5, 2020
Vulnerability identifier: #VU27531
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12389
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due the Firefox content processes did not sufficiently lockdown access control for separate process types. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.
Note, this vulnerability affects Windows versions only.Affected software
Firefox ESR
Mozilla Firefox
Slackware Linux
Opensuse
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
Mozilla Firefox
Slackware Linux
Opensuse
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
How to mitigate CVE-2020-12389
Install updates from vendor's website.
Firefox ESR - update to 68.8.0
Mozilla Firefox - update to 76.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - update to 68.8.0-r0
mozjs68 (Alpine package) - update to 68.8.0-r0
Mozilla Firefox - update to 76.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - update to 68.8.0-r0
mozjs68 (Alpine package) - update to 68.8.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Slackware Linux update for mozilla-firefox
- OpenSUSE Linux update for MozillaFirefox
- Permissions, Privileges, and Access Controls in mozjs68 (Alpine package)
- Permissions, Privileges, and Access Controls in firefox-esr (Alpine package)
- Permissions, Privileges, and Access Controls in firefox (Alpine package)