Permissions, Privileges, and Access Controls in Firefox ESR and Mozilla Firefox - CVE-2020-15663
Published: August 25, 2020 / Updated: August 26, 2020
Firefox ESR
Mozilla Firefox
Mozilla
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due Mozilla Maintenance Service does not check if the updater.exe file has a valid signature before executing it with elevated privileges. A local user with ability to replace the updater.exe file file can execute arbitrary code with SYSTEM privileges.