CVE-2021-29951
Summary
| CVE | CVE-2021-29951 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 14:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296053 Oracle Solaris 11.4 Support Repository Update (SRU) 35.94.4 Missing (CPUJUL2021)
- 375529 Mozilla Thunderbird Security Restriction Bypass Vulnerability (MFSA2021-19)
- 375531 Mozilla Firefox ESR Security Restriction Bypass Vulnerability (MFSA2021-18)
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 506260 Alpine Linux Security Update for thunderbird
- 750119 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:1884-1)
- 750123 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:1886-1)
- 750141 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:1919-1)
- 750166 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:0858-1)
- 750810 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1854-1)
- 750823 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1884-1)