CVE-2021-29951
published 2021-06-24CVE-2021-29951: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.85%
76.7th percentile
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 87.0 | 87.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 87 | 87 |
| mozilla | firefox_esr | < 78.10.1 | 78.10.1 |
| mozilla | firefox_esr | >= unspecified < 78.10.1 | 78.10.1 |
| mozilla | thunderbird | < 78.10.1 | 78.10.1 |
| mozilla | thunderbird | >= unspecified < 78.10.1 | 78.10.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Thunderbird Maintenance Service could have been started or stopped by domain users
vendor_redhat·2021-05-04·CVSS 6.5
CVE-2021-29951 [MEDIUM] CWE-863 Mozilla: Thunderbird Maintenance Service could have been started or stopped by domain users
Mozilla: Thunderbird Maintenance Service could have been started or stopped by domain users
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.
Statement: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected
Packag
Debian
CVE-2021-29951: firefox-esr - The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users wh...
vendor_debian·2021·CVSS 6.5
CVE-2021-29951 [MEDIUM] CVE-2021-29951: firefox-esr - The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users wh...
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Mozilla
Mozilla Foundation Security Advisory 2021-10: CVE-2021-29951
vendor_mozilla·CVSS 6.5
CVE-2021-29951 [MEDIUM] Mozilla Foundation Security Advisory 2021-10: CVE-2021-29951
Mozilla Foundation Security Advisory 2021-10
CVE: CVE-2021-29951
Product: Firefox
Impact: moderate
Fixed in: Firefox 87
Mozilla
Mozilla Foundation Security Advisory 2021-18: CVE-2021-29951
vendor_mozilla·CVSS 6.5
CVE-2021-29951 [MEDIUM] Mozilla Foundation Security Advisory 2021-18: CVE-2021-29951
Mozilla Foundation Security Advisory 2021-18
CVE: CVE-2021-29951
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 78.10.1
Mozilla
Mozilla Foundation Security Advisory 2021-19: CVE-2021-29951
vendor_mozilla·CVSS 6.5
CVE-2021-29951 [MEDIUM] Mozilla Foundation Security Advisory 2021-19: CVE-2021-29951
Mozilla Foundation Security Advisory 2021-19
CVE: CVE-2021-29951
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 78.10.1
GHSA
GHSA-rc27-w7x3-jmp4: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start o
ghsa_unreviewed·2022-05-24
CVE-2021-29951 [MEDIUM] CWE-732 GHSA-rc27-w7x3-jmp4: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start o
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1690062https://www.mozilla.org/security/advisories/mfsa2021-10/https://www.mozilla.org/security/advisories/mfsa2021-18/https://www.mozilla.org/security/advisories/mfsa2021-19/https://bugzilla.mozilla.org/show_bug.cgi?id=1690062https://www.mozilla.org/security/advisories/mfsa2021-10/https://www.mozilla.org/security/advisories/mfsa2021-18/https://www.mozilla.org/security/advisories/mfsa2021-19/
2021-06-24
Published