Mozilla Firefox's update mechanism allowed a medium...
High severity
Unreviewed
Published
Apr 29, 2025
to the GitHub Advisory Database
•
Updated Apr 29, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2025
Published to the GitHub Advisory Database
Apr 29, 2025
Last updated
Apr 29, 2025
Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
References