CVE-2023-29532
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29532?
CVE-2023-29532 refers to a vulnerability where a local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file.
How does CVE-2023-29532 work?
CVE-2023-29532 works by the attacker pointing the Mozilla Maintenance Service at an update file on a malicious SMB server and replacing the update file after the signature check.
Which software is affected by CVE-2023-29532?
Firefox ESR versions up to 102.10, Thunderbird versions up to 102.10, Firefox versions up to 112, and Firefox for Android versions up to 112 are affected by CVE-2023-29532.
What is the severity of CVE-2023-29532?
CVE-2023-29532 has a severity value of 7, which is classified as high.
How can I mitigate the vulnerability CVE-2023-29532?
To mitigate CVE-2023-29532, it is recommended to update to the fixed version of the affected software.