#VU52852 Security restrictions bypass in Firefox ESR - CVE-2021-29951
Published: May 4, 2021
Firefox ESR
Mozilla
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to the way Mozilla Maintenance Service is installed in the Windows operating system. After installation the Mozilla Maintenance Service is granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. A local domain user can spam the "Stop" command and prevent the browser update service from operating.
The vulnerability affects only Firefox ESR installed on operating system Windows 10 build 1709 and older.