CVE-2019-11753 describes a privilege escalation vulnerability affecting Firefox and Firefox ESR on Windows systems. It arises when Firefox is installed to a user-writable location, allowing an unprivileged attacker to manipulate the Mozilla Maintenance Service during an update, leading to the execution of altered code with elevated privileges. This vulnerability has a CVSS score of 7.8 (High) due to its local attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While it has garnered some community discussion and media coverage, there is currently no public exploit code available, and it is not listed on CISA's KEV catalog, indicating no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 69.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 68.0, < 68.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.