CVE-2019-11753
Last modified
CVE-2019-11753 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenance service can run with elevated privileges during the update process due to a lack of integrity checks. This allows for privilege escalation if the executable has been replaced locally. <br>*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 60.9.0 |
| Mozilla | Firefox | < 69.0 |
| Mozilla | Firefox Esr | >= 68.0, < 68.1.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1574980Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-25/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-26/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-27/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1574980Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-25/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-26/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-27/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11753?
How severe is CVE-2019-11753?
How do I fix CVE-2019-11753?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11748WebRTC in Firefox will honor persisted permissions given to …6.5
- CVE-2019-11749A vulnerability exists in WebRTC where malicious web content…4.3
- CVE-2019-1175An elevation of privilege vulnerability exists in the way th…7
- CVE-2019-11750A type confusion vulnerability exists in Spidermonkey, which…6.5
- CVE-2019-11751Logging-related command line parameters are not properly san…8.8
- CVE-2019-11752It is possible to delete an IndexedDB key value and subseque…8.8
- CVE-2019-11754When the pointer lock is enabled by a website though request…4.3
- CVE-2019-11755A crafted S/MIME message consisting of an inner encryption l…7.5
- CVE-2019-11756Improper refcounting of soft token session objects could cau…8.8
- CVE-2019-11757When following the value's prototype chain, it was possible …8.8
- CVE-2019-11758Mozilla community member Philipp reported a memory safety bu…8.8
- CVE-2019-11759An attacker could have caused 4 bytes of HMAC output to be w…8.8
Are you affected by CVE-2019-11753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
