#VU52852 Security restrictions bypass in Firefox ESR - CVE-2021-29951 

 

#VU52852 Security restrictions bypass in Firefox ESR - CVE-2021-29951

Published: May 4, 2021


Vulnerability identifier: #VU52852
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-29951
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to the way Mozilla Maintenance Service is installed in the Windows operating system. After installation the Mozilla Maintenance Service is granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. A local domain user can spam  the "Stop" command and prevent the browser update service from operating.

The vulnerability affects only Firefox ESR installed on operating system Windows 10 build 1709 and older.


Remediation

Install updates from vendor's website.

External links