HomeSecurityMozilla Firefox: Fixes bug that gave administrator privileges

Mozilla Firefox: Fixes bug that granted administrator privileges

A security update has been released by Mozilla to address a high-severity Firefox privilege escalation vulnerability identified by the company's Maintenance Department.

Mozilla Firefox

See also: Mozilla retires VR browser Firefox Reality

The Mozilla Maintenance is an optional Firefox and Thunderbird service that enables background application updates.

This provides Firefox users with a seamless update experience where they are no longer required to click " Yes " on the " Windows User Account Control (UAC) " dialog box before updating their web browser or email client.

Mozilla fixed the privilege escalation security flaw, identified as CVE-2022-22753, with the release of Firefox 97.

Successful exploitation on unpatched systems could allow attackers to escalate their privileges to NT AUTHORITY\SYSTEM, the highest level of privilege on a Windows.

There was a Time-of-Check Time-of-Use bug in the Maintenance (Update) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access,” Mozilla explained.

This bug only affects Firefox on Windows. Other operating systems are not affected.

error

Mozilla also said that Firefox 97 addresses multiple memory safety bugs identified by Mozilla developers and the community in Firefox 96 and Firefox ESR 91.5.

Firefox 97 also adds new features and improvements.

The new version comes with features like support for the new scrollbar style in Windows 11 and fixes, including improvements to macOS, which makes opening and switching to new tabs faster.

Firefox 97 also removes support for directly generating PostScript for printing on Linux, although printing to PostScript printers is still available as a supported option.

See also: Firefox: Websites not loading for some users – What is the solution?

In December, Mozilla also fixed a critical memory corruption bug affecting the cross-platform Network Security Services (NSS) cryptographic libraries.

On systems running vulnerable versions of Firefox, the exploit could lead to a buffer overflow, with impacts ranging from program errors and arbitrary code execution to security software bypass if code execution is achieved.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS