CVE-2023-29532
Published: Jun 19, 2023
Modified: Dec 11, 2024
Description
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 112 |
Mozilla | Firefox ESR | affected unspecified - < 102.10 |
Mozilla | Thunderbird | affected unspecified - < 102.10 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now