Mozilla Foundation Security Advisory 2016-40

Privilege escalation through file deletion by Maintenance Service updater

Announced
April 26, 2016
Reporter
Holger Fuhrmannek
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 46

Description

Security researcher Holger Fuhrmannek reported an issue where the Mozilla Maintenance Service updater on Windows can delete arbitrary files because of its privileged system access. This file deletion can then potentially be used for further privilege escalation. This flaw requires users to execute a locally saved file in order for it to be triggered.

This issue does not affect non-Windows operating systems.

References