CVE-2019-11736
published 2019-09-27CVE-2019-11736: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local…
PriorityP428high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.21%
11.2th percentile
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. *Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | < 69.0 | 69.0 |
| mozilla | firefox | >= unspecified < 69 | 69 |
| mozilla | firefox_esr | < 68.1.0 | 68.1.0 |
| mozilla | firefox_esr | >= unspecified < 68.1 | 68.1 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0LOW
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: File manipulation and privilege escalation in Mozilla Maintenance Service
vendor_redhat·2019-09-03·CVSS 7.0
CVE-2019-11736 [HIGH] CWE-59 Mozilla: File manipulation and privilege escalation in Mozilla Maintenance Service
Mozilla: File manipulation and privilege escalation in Mozilla Maintenance Service
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. *Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 an
Debian
CVE-2019-11736: firefox - The Mozilla Maintenance Service does not guard against files being hardlinked to...
vendor_debian·2019·CVSS 7.0
CVE-2019-11736 [HIGH] CVE-2019-11736: firefox - The Mozilla Maintenance Service does not guard against files being hardlinked to...
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. *Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Scope: local
sid: resolved
GHSA
GHSA-g4fc-6wpg-63m2: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement o
ghsa_unreviewed·2022-05-24
CVE-2019-11736 [HIGH] CWE-362 GHSA-g4fc-6wpg-63m2: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement o
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. *Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
OSV
CVE-2019-11736: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement o
osv·2019-09-27·CVSS 7.0
CVE-2019-11736 [HIGH] CVE-2019-11736: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement o
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. *Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11736 Mozilla: File manipulation and privilege escalation in Mozilla Maintenance Service
bugzilla·2019-09-04·CVSS 7.0
CVE-2019-11736 [HIGH] CVE-2019-11736 Mozilla: File manipulation and privilege escalation in Mozilla Maintenance Service
CVE-2019-11736 Mozilla: File manipulation and privilege escalation in Mozilla Maintenance Service
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the `updates` directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access.
*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*
External Reference:
ht
Bugzilla
Firefox 69.0 is available
bugzilla·2019-09-03·CVSS 9.8
CVE-2019-11751 [CRITICAL] Firefox 69.0 is available
Firefox 69.0 is available
Description of problem:
Firefox 69.0 is available
Version-Release number of selected component (if applicable):
69.0
Additional info:
Release Notes: https://www.mozilla.org/en-US/firefox/69.0/releasenotes/
Security Advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/
Security
- CVE-2019-11751: Malicious code execution through command line parameters
- CVE-2019-11746: Use-after-free while manipulating video
- CVE-2019-11744: XSS by breaking out of title and textarea elements using innerHTML
- CVE-2019-11742: Same-origin policy violation with SVG filters and canvas to steal cross-origin images
- CVE-2019-11736: File manipulation and privilege escalation in Mozilla Maintenance Service
- CVE-2019-11753: Privilege escalation with Mozilla Maint
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1551913https://bugzilla.mozilla.org/show_bug.cgi?id=1552206https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-26/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1551913https://bugzilla.mozilla.org/show_bug.cgi?id=1552206https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-26/
2019-09-27
Published