Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox ESR - CVE-2020-15663
Published: August 25, 2020 / Updated: August 26, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due Mozilla Maintenance Service does not check if the updater.exe file has a valid signature before executing it with elevated privileges. A local user with ability to replace the updater.exe file file can execute arbitrary code with SYSTEM privileges.
Affected software
Firefox ESR
Slackware Linux
Opensuse
firefox (Alpine package)
firefox-esr (Alpine package)
Mozilla Thunderbird
How to mitigate CVE-2020-15663
Firefox ESR - addressed in versions 68.12.0, 78.2.0
Mozilla Thunderbird - addressed in versions 68.12.0, 78.2.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- Permissions, Privileges, and Access Controls in firefox-esr (Alpine package)
- Permissions, Privileges, and Access Controls in firefox (Alpine package)
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Slackware Linux update for mozilla-thunderbird