Executive Summary

Informations
NameCVE-2019-11736First vendor Publication2019-09-27
VendorCveLast vendor Modification2019-10-05

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score4.4Attack RangeLocal
Cvss Impact Score6.4Attack ComplexityMedium
Cvss Expoit Score3.4AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access.
*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11736

CWE : Common Weakness Enumeration

%idName
100 %CWE-362Race Condition

CPE : Common Platform Enumeration

TypeDescriptionCount
Application420
Application124
Os1

Sources (Detail)

SourceUrl
CONFIRM https://www.mozilla.org/security/advisories/mfsa2019-25/
https://www.mozilla.org/security/advisories/mfsa2019-26/
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=1551913
https://bugzilla.mozilla.org/show_bug.cgi?id=1552206
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
DateInformations
2019-10-06 21:20:41
  • Multiple Updates
2019-10-05 12:11:01
  • Multiple Updates
2019-10-02 17:18:49
  • Multiple Updates
2019-09-28 12:10:54
  • First insertion