Security restrictions bypass in Firefox ESR - CVE-2021-29951

 

Security restrictions bypass in Firefox ESR - CVE-2021-29951

Published: May 4, 2021


Vulnerability identifier: #VU52852
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29951
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to the way Mozilla Maintenance Service is installed in the Windows operating system. After installation the Mozilla Maintenance Service is granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. A local domain user can spam  the "Stop" command and prevent the browser update service from operating.

The vulnerability affects only Firefox ESR installed on operating system Windows 10 build 1709 and older.


Affected software

Firefox ESR
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
IBM Cloud Application Performance Management (APM)
Mozilla Thunderbird
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaFirefox-translations-other
MozillaFirefox-translations-common
MozillaFirefox-devel
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox

How to mitigate CVE-2021-29951

Install updates from vendor's website.

Firefox ESR - update to 78.10.1
Mozilla Thunderbird - update to 78.10.1
MozillaThunderbird - update to 78.10.2-8.27.1
MozillaThunderbird-debuginfo - update to 78.10.2-8.27.1
MozillaThunderbird-debugsource - update to 78.10.2-8.27.1
MozillaThunderbird-translations-common - update to 78.10.2-8.27.1
MozillaThunderbird-translations-other - update to 78.10.2-8.27.1
MozillaFirefox-translations-other - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1
MozillaFirefox-translations-common - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1, 78.11.0-112.62.1
MozillaFirefox-devel - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-112.62.1
MozillaFirefox-debugsource - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-112.62.1
MozillaFirefox-debuginfo - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1, 78.11.0-112.62.1
MozillaFirefox - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1, 78.11.0-112.62.1

External References

Related Security Bulletins