CVE-2023-29532: Medium severity thunderbird vulnerability
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Other sources
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-29531
- CVE-2023-29532
- CVE-2023-29533
- CVE-2023-1999
- CVE-2023-29535
- CVE-2023-29536
- CVE-2023-0547
- CVE-2023-29479
- CVE-2023-29539
- CVE-2023-29541
- CVE-2023-29542
- CVE-2023-29545
- CVE-2023-1945
- CVE-2023-29548
- CVE-2023-29550
- CVE-2023-29534
- CVE-2023-29537
- CVE-2023-29538
- CVE-2023-29540
- CVE-2023-29543
- CVE-2023-29544
- CVE-2023-29546
- CVE-2023-29547
- CVE-2023-29549
- CVE-2023-29551
Frequently Asked Questions
What is CVE-2023-29532?
CVE-2023-29532 refers to a vulnerability where a local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file.
How does CVE-2023-29532 work?
CVE-2023-29532 works by the attacker pointing the Mozilla Maintenance Service at an update file on a malicious SMB server and replacing the update file after the signature check.
Which software is affected by CVE-2023-29532?
Firefox ESR versions up to 102.10, Thunderbird versions up to 102.10, Firefox versions up to 112, and Firefox for Android versions up to 112 are affected by CVE-2023-29532.
What is the severity of CVE-2023-29532?
CVE-2023-29532 has a severity value of 7, which is classified as high.
How can I mitigate the vulnerability CVE-2023-29532?
To mitigate CVE-2023-29532, it is recommended to update to the fixed version of the affected software.