CVE-2019-11736
CVSS V2 Medium 4.4
CVSS V3 High 7
Description
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. <br>*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Overview
- CVE ID
- CVE-2019-11736
- Assigner
- security@mozilla.org
- Vulnerability Status
- Modified
- Published Version
- 2019-09-27T18:15:11
- Last Modified Date
- 2019-10-05T06:15:13
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
AND | ||||
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 1 | OR | 69.0 | |
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | 1 | OR | 68.1.0 | |
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | 0 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:L/AC:M/Au:N/C:P/I:P/A:P
- Access Vector
- LOCAL
- Access Compatibility
- MEDIUM
- Authentication
- NONE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- PARTIAL
- Availability Impact
- PARTIAL
- Base Score
- 4.4
- Severity
- MEDIUM
- Exploitability Score
- 3.4
- Impact Score
- 6.4
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Vector
- LOCAL
- Attack Compatibility
- HIGH
- Privileges Required
- LOW
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- HIGH
- Base Score
- 7
- Base Severity
- HIGH
- Exploitability Score
- 1
- Impact Score
- 5.9
References
Reference URL | Reference Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1552206 | Issue Tracking Permissions Required Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1551913 | Issue Tracking Permissions Required Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-25/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-26/ | Vendor Advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html | |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2019-11736 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11736 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 17:15:54 | Added to TrackCVE | |||
2022-12-04 03:17:40 | 2019-09-27T18:15Z | 2019-09-27T18:15:11 | CVE Published Date | updated |
2022-12-04 03:17:40 | 2019-10-05T06:15:13 | CVE Modified Date | updated | |
2022-12-04 03:17:40 | Modified | Vulnerability Status | updated |