CVE-2023-29532

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2023
Last modified:
11/12/2024

Description

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.<br /> <br /> *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 112.0 (excluding)
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* 102.10 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 102.10 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*