Security restrictions bypass in Firefox ESR - CVE-2021-29951
Published: May 4, 2021
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to the way Mozilla Maintenance Service is installed in the Windows operating system. After installation the Mozilla Maintenance Service is granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. A local domain user can spam the "Stop" command and prevent the browser update service from operating.
The vulnerability affects only Firefox ESR installed on operating system Windows 10 build 1709 and older.
Affected software
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
IBM Cloud Application Performance Management (APM)
Mozilla Thunderbird
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaFirefox-translations-other
MozillaFirefox-translations-common
MozillaFirefox-devel
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox
How to mitigate CVE-2021-29951
Mozilla Thunderbird - update to 78.10.1
MozillaThunderbird - update to 78.10.2-8.27.1
MozillaThunderbird-debuginfo - update to 78.10.2-8.27.1
MozillaThunderbird-debugsource - update to 78.10.2-8.27.1
MozillaThunderbird-translations-common - update to 78.10.2-8.27.1
MozillaThunderbird-translations-other - update to 78.10.2-8.27.1
MozillaFirefox-translations-other - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1
MozillaFirefox-translations-common - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1, 78.11.0-112.62.1
MozillaFirefox-devel - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-112.62.1
MozillaFirefox-debugsource - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-112.62.1
MozillaFirefox-debuginfo - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1, 78.11.0-112.62.1
MozillaFirefox - addressed in versions 78.11.0-3.144.1, 78.11.0-8.43.1, 78.11.0-78.131.1, 78.11.0-112.62.1
External References
Related Security Bulletins
- Security restrictions bypass in Firefox ESR
- Security restrictions bypass in Mozilla Thunderbird
- SUSE update for MozillaThunderbird
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- Multiple vulnerabilities in IBM Application Performance Management