CVE-2019-11753
published 2019-09-27CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | < 60.9.0 | 60.9.0 |
| mozilla | firefox | < 69.0 | 69.0 |
| mozilla | firefox | >= unspecified < 69 | 69 |
| mozilla | firefox_esr | >= 68.0 < 68.1.0 | 68.1.0 |
| mozilla | firefox_esr | >= unspecified < 60.9 | 60.9 |
| mozilla | firefox_esr | >= unspecified < 68.1 | 68.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h86-hhcq-m432: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged user
ghsa_unreviewed·2022-05-24
CVE-2019-11753 [HIGH] CWE-354 GHSA-8h86-hhcq-m432: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged user
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69, Firefox ESR < 60.9, and Firefox ESR < 68.1.
OSV
CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged user
osv·2019-09-27·CVSS 7.8
CVE-2019-11753 [HIGH] CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged user
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Red Hat
Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location
vendor_redhat·2019-09-03·CVSS 7.8
CVE-2019-11753 [HIGH] CWE-282 Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location
Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 6
Debian
CVE-2019-11753: firefox - The Firefox installer allows Firefox to be installed to a custom user writable l...
vendor_debian·2019·CVSS 7.8
CVE-2019-11753 [HIGH] CVE-2019-11753: firefox - The Firefox installer allows Firefox to be installed to a custom user writable l...
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
Mozilla Maintenance Service Privilege Escalation via updater.exe if Firefox is installed in non-default location
bugzilla·2020-06-03·CVSS 7.8
CVE-2019-11753 [HIGH] Mozilla Maintenance Service Privilege Escalation via updater.exe if Firefox is installed in non-default location
Mozilla Maintenance Service Privilege Escalation via updater.exe if Firefox is installed in non-default location
Created attachment 9154016
poc.zip
This report is inspired by CVE-2019-11753 (Bug 1574980) and CVE-2017-7766 (Bug 1342742).
Summary: If a user has installed Firefox to a standard-user-writable location, then a local attacker who already has non-admin privilege can escalate his privilege to SYSTEM.
Detail: Since the Firefox installation path is user-writable, a local attacker can replace any files in the installation path. What we need to replace are `updater.exe` and `updater.ini`. Although the Maintenance Service checks if `updater.exe` contains an identity string and is signed by Mozilla, it doesn't check its file version. Thus, we can replace the currently installed `upda
Bugzilla
CVE-2019-11753 Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location
bugzilla·2019-09-04·CVSS 7.8
CVE-2019-11753 [HIGH] CVE-2019-11753 Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location
CVE-2019-11753 Mozilla: Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally.
*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*
External Reference:
Bugzilla
Firefox 69.0 is available
bugzilla·2019-09-03·CVSS 9.8
CVE-2019-11751 [CRITICAL] Firefox 69.0 is available
Firefox 69.0 is available
Description of problem:
Firefox 69.0 is available
Version-Release number of selected component (if applicable):
69.0
Additional info:
Release Notes: https://www.mozilla.org/en-US/firefox/69.0/releasenotes/
Security Advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/
Security
- CVE-2019-11751: Malicious code execution through command line parameters
- CVE-2019-11746: Use-after-free while manipulating video
- CVE-2019-11744: XSS by breaking out of title and textarea elements using innerHTML
- CVE-2019-11742: Same-origin policy violation with SVG filters and canvas to steal cross-origin images
- CVE-2019-11736: File manipulation and privilege escalation in Mozilla Maintenance Service
- CVE-2019-11753: Privilege escalation with Mozilla Maint
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1574980https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-26/https://www.mozilla.org/security/advisories/mfsa2019-27/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1574980https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-26/https://www.mozilla.org/security/advisories/mfsa2019-27/
2019-09-27
Published