CVE-2019-11753Improper Validation of Integrity Check Value in Mozilla Firefox

Severity
7.8HIGHNVD
EPSS
0.1%
top 80.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 24

Description

The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if th

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified69
NVDmozilla/firefox< 60.9.0+1
CVEListV5mozilla/firefox_esrunspecified60.9+1
NVDmozilla/firefox_esr68.068.1.0

🔴Vulnerability Details

2
GHSA
GHSA-8h86-hhcq-m432: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged user2022-05-24
OSV
CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged user2019-09-27

📋Vendor Advisories

2
Red Hat
Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location2019-09-03
Debian
CVE-2019-11753: firefox - The Firefox installer allows Firefox to be installed to a custom user writable l...2019

💬Community

3
Bugzilla
Mozilla Maintenance Service Privilege Escalation via updater.exe if Firefox is installed in non-default location2020-06-03
Bugzilla
CVE-2019-11753 Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location2019-09-04
Bugzilla
Firefox 69.0 is available2019-09-03