CVE-2019-11753
Description
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities fixed in Mozilla Firefox ESR (x64) (60.9.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox ESR (60.9.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox ESR (x64) (68.1.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox ESR (68.1.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox (x64) (69.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox (x64) (69.0.1) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox (69.0.1) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox (69.0) | Windows |
| Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (69.0) | Mac |
| Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (69.0.1) | Mac |
| Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (69.0.2) | Mac |
| Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (69.0.3) | Mac |
| Multiple Vulnerabilities are affected in Firefox ESR for Mac 60.7.2 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 60.7.2 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 68.0.1 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 68.6.0 | Mac |
| Multiple Vulnerabilities are affected in Firefox ESR for Mac 68.0.1 | Mac |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 68.1 | Mac |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 60.9 | Mac |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-60.9.0-109.86.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debuginfo-60.9.0-109.86.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debugsource-60.9.0-109.86.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-translations-common-60.9.0-109.86.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2620-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-68.1.0-109.89.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2620-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-branding-SLE-68-32.8.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2620-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debuginfo-68.1.0-109.89.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2620-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debugsource-68.1.0-109.89.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2620-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-translations-common-68.1.0-109.89.1.x86_64.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Server 12-SP5) MozillaFirefox-60.9.0-109.86.1.x86_64_12_SP5.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Server 12-SP5) MozillaFirefox-debuginfo-60.9.0-109.86.1.x86_64_12_SP5.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Server 12-SP5) MozillaFirefox-debugsource-60.9.0-109.86.1.x86_64_12_SP5.rpm | Linux |
| SUSE-SU-2019:2436-1(SUSE Linux Enterprise Server 12-SP5) MozillaFirefox-translations-common-60.9.0-109.86.1.x86_64_12_SP5.rpm | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-310844 | Mozilla Firefox ESR (x64) (60.9.0) |
| PATCH-310843 | Mozilla Firefox ESR (60.9.0) |
| PATCH-310847 | Mozilla Firefox ESR (x64) (68.1.0) |
| PATCH-310845 | Mozilla Firefox ESR (68.1.0) |
| PATCH-310840 | Mozilla Firefox (x64) (69.0) |
| PATCH-310979 | Mozilla Firefox (x64) (69.0.1) |
| PATCH-310978 | Mozilla Firefox (69.0.1) |
| PATCH-311220 | Mozilla Firefox (69.0.3) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-611808 | Mozilla Firefox ESR for MAC 128.14.0 |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
| PATCH-611808 | Mozilla Firefox ESR for MAC 128.14.0 |
| PATCH-612783 | Mozilla Firefox For Mac (145.0.1) |
| PATCH-612783 | Mozilla Firefox For Mac (145.0.1) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234