Unrated severityNVD Advisory· Published Jun 24, 2021· Updated Aug 3, 2024
CVE-2021-29951
CVE-2021-29951
Description
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.
Affected products
38- osv-coords35 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/MozillaFirefox&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3
< 78.11.0-lp152.2.58.1+ 34 more
- (no CPE)range: < 78.11.0-lp152.2.58.1
- (no CPE)range: < 78.11.0-8.43.1
- (no CPE)range: < 78.10.2-8.27.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-8.43.1
- (no CPE)range: < 78.11.0-8.43.1
- (no CPE)range: < 78.11.0-78.131.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-3.144.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.11.0-112.62.1
- (no CPE)range: < 78.10.2-8.27.1
- (no CPE)range: < 78.10.2-8.27.1
- Range: unspecified
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bugzilla.mozilla.org/show_bug.cgimitrex_refsource_MISC
- www.mozilla.org/security/advisories/mfsa2021-10/mitrex_refsource_MISC
- www.mozilla.org/security/advisories/mfsa2021-18/mitrex_refsource_MISC
- www.mozilla.org/security/advisories/mfsa2021-19/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.