#VU74821 Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox ESR - CVE-2023-29532
Published: April 11, 2023
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the way Mozilla Maintenance Service handles write-locks when downloading updates from a SMB server. A local user can apply an unsigned update file by pointing the service at an update file on a malicious SMB server.
The vulnerability affects only Firefox for Windows.