#VU20822 Improper validation of integrity check value in Mozilla Firefox - CVE-2019-11753

 

#VU20822 Improper validation of integrity check value in Mozilla Firefox - CVE-2019-11753

Published: September 3, 2019


Vulnerability identifier: #VU20822
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-11753
CWE-ID: CWE-354
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Software vendor:
Mozilla

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the Mozilla Maintenance Service does not check integrity of the binary files that were installed into a custom and unprotected folder on the system. A local user can manipulate the Mozilla Maintenance Service to update this unprotected location and escalate privilege on the system.

Note, the vulnerability affects Windows installation only.


Remediation

Install updates from vendor's website.

External links