CVE-2019-11736 describes a privilege escalation vulnerability affecting Mozilla Firefox and Firefox ESR on Windows systems prior to versions 69 and 68.1 respectively. The Mozilla Maintenance Service, which runs with privileged access, is susceptible to hardlink attacks and a race condition during link checks, allowing an unprivileged local attacker to replace local files, including the service's executable. This vulnerability carries a CVSS score of 7.0 (HIGH) due to its local attack vector, high impact on confidentiality, integrity, and availability, and high attack complexity. While the vulnerability is significant, there is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. Community discussion and media coverage are minimal, suggesting limited public awareness or active threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 69.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 68.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.