#VU52338 Insecure Inherited Permissions in Mozilla Firefox and Firefox ESR - CVE-2021-23999

 

#VU52338 Insecure Inherited Permissions in Mozilla Firefox and Firefox ESR - CVE-2021-23999

Published: April 19, 2021


Vulnerability identifier: #VU52338
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-23999
CWE-ID: CWE-277
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

the vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to the way Firefox handles Blob URLs. If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content.


Remediation

Install updates from vendor's website.

External links