NA

CVE-2023-4052

Published: 01/08/2023 Updated: 07/08/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox esr

Vendor Advisories

Mozilla Foundation Security Advisory 2023-33 Security Vulnerabilities fixed in Thunderbird 1151 Announced August 2, 2023 Impact high Products Thunderbird Fixed in Thunderbird 1151 ...
Description<!---->A flaw was found in Mozilla The Mozilla Foundation Security Advisory described the issue of the Firefox updater creating a directory writable by non-privileged users When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account This could be combined wi ...