CVE-2023-29532
published 2023-06-19CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.18%
8.4th percentile
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 112.0 | 112.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 112 | 112 |
| mozilla | firefox_esr | < 102.10 | 102.10 |
| mozilla | firefox_esr | >= unspecified < 102.10 | 102.10 |
| mozilla | thunderbird | < 102.10 | 102.10 |
| mozilla | thunderbird | >= unspecified < 102.10 | 102.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malici
osv·2023-06-19·CVSS 5.5
CVE-2023-29532 [MEDIUM] CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malici
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
GHSA
GHSA-f2q9-pfpx-m83g: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malici
ghsa_unreviewed·2023-06-19
CVE-2023-29532 [MEDIUM] GHSA-f2q9-pfpx-m83g: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malici
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Red Hat
Mozilla: Mozilla Maintenance Service Write-lock bypass
vendor_redhat·2023-04-11·CVSS 5.5
CVE-2023-29532 [MEDIUM] CWE-779 Mozilla: Mozilla Maintenance Service Write-lock bypass
Mozilla: Mozilla Maintenance Service Write-lock bypass
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
The Mozilla Foundation Security Advisory describes this flaw as:
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicio
Debian
CVE-2023-29532: firefox - A local attacker can trick the Mozilla Maintenance Service into applying an unsi...
vendor_debian·2023·CVSS 5.5
CVE-2023-29532 [MEDIUM] CVE-2023-29532: firefox - A local attacker can trick the Mozilla Maintenance Service into applying an unsi...
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-13: CVE-2023-29532
vendor_mozilla·CVSS 5.5
CVE-2023-29532 [MEDIUM] Mozilla Foundation Security Advisory 2023-13: CVE-2023-29532
Mozilla Foundation Security Advisory 2023-13
CVE: CVE-2023-29532
Product: Firefox, Firefox for Android, Focus for Android
Impact: high
Fixed in: Firefox 112
Firefox for Android 112
Focus for Android 112
Mozilla
Mozilla Foundation Security Advisory 2023-14: CVE-2023-29532
vendor_mozilla·CVSS 5.5
CVE-2023-29532 [MEDIUM] Mozilla Foundation Security Advisory 2023-14: CVE-2023-29532
Mozilla Foundation Security Advisory 2023-14
CVE: CVE-2023-29532
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-29532
vendor_mozilla·CVSS 5.5
CVE-2023-29532 [MEDIUM] Mozilla Foundation Security Advisory 2023-15: CVE-2023-29532
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-29532
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1806394https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/https://bugzilla.mozilla.org/show_bug.cgi?id=1806394https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/
2023-06-19
Published