CVE-2019-17009
published 2020-01-08CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.4th percentile
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 71.0 | 71.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 68.3 | 68.3 |
| mozilla | firefox_esr | — | — |
| mozilla | thunderbird | < 68.3 | 68.3 |
| mozilla | thunderbird | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Updater temporary files accessible to unprivileged processes
vendor_redhat·2019-12-03·CVSS 7.8
CVE-2019-17009 [HIGH] CWE-377 Mozilla: Updater temporary files accessible to unprivileged processes
Mozilla: Updater temporary files accessible to unprivileged processes
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Li
Debian
CVE-2019-17009: firefox - When running, the updater service wrote status and log files to an unrestricted ...
vendor_debian·2019·CVSS 7.8
CVE-2019-17009 [HIGH] CVE-2019-17009: firefox - When running, the updater service wrote status and log files to an unrestricted ...
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Scope: local
sid: resolved
GHSA
GHSA-9wr8-jjcr-qw4x: When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and e
ghsa_unreviewed·2022-05-24
CVE-2019-17009 [MEDIUM] GHSA-9wr8-jjcr-qw4x: When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and e
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
OSV
CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and e
osv·2020-01-08·CVSS 7.8
CVE-2019-17009 [HIGH] CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and e
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17009 Mozilla: Updater temporary files accessible to unprivileged processes
bugzilla·2019-12-04·CVSS 7.8
CVE-2019-17009 [HIGH] CVE-2019-17009 Mozilla: Updater temporary files accessible to unprivileged processes
CVE-2019-17009 Mozilla: Updater temporary files accessible to unprivileged processes
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-37/#CVE-2019-17009
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Robert Strong
Bugzilla
Write log files and update.status file to restricted directory and copy it to the final location after the update finishes
bugzilla·2018-11-28
[MEDIUM] Write log files and update.status file to restricted directory and copy it to the final location after the update finishes
Write log files and update.status file to restricted directory and copy it to the final location after the update finishes
To lessen the attack surface when writing files in unrestricted locations such as the log file and the update.status file the updater should write these files to a restricted location and then copy them to the final location.
*edit* s/then copy them to the final location/the unelevated updater should copy them to the update directory/
Discussion:
[Tracking Requested - why for this release]:
Long standing security bug.
---
Created attachment 9094251
Bug 1510494 - write elevated updater log and status files to a new directory in the Maintenance Service directory. r=agashlin,mhowell
---
Comment on attachment 9094251
Bug 1510494 - write elevated updater log and sta
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00001.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1510494https://www.mozilla.org/security/advisories/mfsa2019-36/https://www.mozilla.org/security/advisories/mfsa2019-37/https://www.mozilla.org/security/advisories/mfsa2019-38/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00001.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1510494https://www.mozilla.org/security/advisories/mfsa2019-36/https://www.mozilla.org/security/advisories/mfsa2019-37/https://www.mozilla.org/security/advisories/mfsa2019-38/
2020-01-08
Published