CVE-2019-17009: High severity thunderbird vulnerability
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.
Other sources
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2019-17009.
What is the severity level of CVE-2019-17009?
The severity level of CVE-2019-17009 is high.
Which operating systems are affected by CVE-2019-17009?
Only Windows operating systems are affected by CVE-2019-17009.
Which software products are affected by CVE-2019-17009?
Mozilla Firefox ESR, Mozilla Thunderbird, and Mozilla Firefox versions up to 71.0 are affected by CVE-2019-17009.
How can this vulnerability be exploited?
This vulnerability can be exploited by an unprivileged process with local system access locating and exploiting a vulnerability in file handling in the updater service.