#VU78852 Insecure Inherited Permissions in Mozilla Firefox and Firefox ESR - CVE-2023-4052
Published: August 1, 2023 / Updated: August 2, 2023
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to Firefox uninstaller follows symbolic links when removing files from directory created by the application updater that is writable by non-privileged users. A local user can create symbolic links to critical files on the system and delete them when uninstalling Firefox.
Note, the vulnerability affects Windows installations only.