cbcvebase.
CVE-2021-29951
published 2021-06-24

CVE-2021-29951: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop…

PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.85%
76.7th percentile
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianfirefox-esr
debianthunderbird
mozillafirefox< 87.087.0
mozillafirefox
mozillafirefox>= unspecified < 8787
mozillafirefox_esr< 78.10.178.10.1
mozillafirefox_esr>= unspecified < 78.10.178.10.1
mozillathunderbird< 78.10.178.10.1
mozillathunderbird>= unspecified < 78.10.178.10.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.