Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-12389

 

Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-12389

Published: May 5, 2020


Vulnerability identifier: #VU27531
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12389
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due the Firefox content processes did not sufficiently lockdown access control for separate process types. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.

Note, this vulnerability affects Windows versions only.

Affected software

Firefox ESR
Mozilla Firefox
Slackware Linux
Opensuse
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)

How to mitigate CVE-2020-12389

Install updates from vendor's website.

Firefox ESR - update to 68.8.0
Mozilla Firefox - update to 76.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - update to 68.8.0-r0
mozjs68 (Alpine package) - update to 68.8.0-r0

External References

Related Security Bulletins