Vulnerability CVE-2021-29951


Published: 2021-06-24

Description:
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.

Type:

CWE-732

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None

 References:
https://bugzilla.mozilla.org/show_bug.cgi?id=1690062
https://www.mozilla.org/security/advisories/mfsa2021-10/
https://www.mozilla.org/security/advisories/mfsa2021-19/
https://www.mozilla.org/security/advisories/mfsa2021-18/

Copyright 2024, cxsecurity.com

 

Back to Top