VYPR

Mozilla Maintenance Service

by Mozilla Corporation

CVEs (3)

  • CVE-2019-11753HigSep 27, 2019
    risk 0.51cvss 7.8epss 0.00

    The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance…

  • CVE-2019-11736HigSep 27, 2019
    risk 0.46cvss 7.0epss 0.00

    The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race…

  • CVE-2023-29532MedJun 19, 2023
    risk 0.36cvss 5.5epss 0.00

    A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by…