Mozilla patches a vulnerability in Firefox that helps hackers gain admin rights of Windows
This vulnerability resides in the Mozilla Maintenance Service, so if successfully exploited, hackers can gain admin rights of the system.
Mozilla Maintenance Service is an optional service of Firefox and Thunderbird that keeps application updates running in the background. It provides Firefox users with a seamless update experience, without the need to click the "Yes" option in Windows User Account Control (UAC) before updating their web browser or email client.
Mozilla has patched the privilege escalation vulnerability tracked under code CVE-2022-22753 in the just released Fifefox 97 update.
When successfully exploiting CVE-2022-22753 on unpatched computers, hackers can take over NT AUTHORITYSYSTEM, the highest control on Windows systems.
"A Time-of-Check Time-of-Use bug exists in the Mozilla Maintenance Service that can be abused to give users write permission to an arbitrary directory. This can be used to elevate access permissions. SYSTEM level," Mozilla shared. "This bug only affects Firefox on Windows. Other operating systems are not affected."
Mozilla also adds that Firefox 97 has resolved many of the memory-safe bugs found by the Mozilla community and developers in Firefox 96 and Firefox ESR 91.5.
Firefox 97 adds some new features and improvements
Besides bug fixes, the new Firefox update also brings a number of new features and improvements. The first is the new style scrollbars on Windows 11 and the next is an improvement in loading system fonts on macOS that makes opening and switching new tabs faster.
You should read it
- Discovering a new zero-day vulnerability in Steam, more than 100 million users may be affected
- New privilege escalation vulnerability called 'Dirty Pipe' is threatening all Linux distros
- Firefox 16 was released again after updating the vulnerability patch
- Firefox releases urgent update to patch zero-day vulnerability being exploited by hackers
- Mozilla released Firefox 62.0.2 to fix the problem of corrupting the operating system
- What to do when Firefox crashes?
- FireFox 54 version improves performance, speed, and security enhancement
- Firefox 58 and new features help improve performance
May be interested
- How to launch Admin rights application for User account in Windows?when many people use the same computer, creating multiple user accounts next to the admin account is a good option. the problem is that when using a user account, there are some features that will be limited. however, if you want to grant permission for a certain user right to use as admin but do not want to give admin account password to that person, you can refer to our guide below.
- How to assign Administrator permissions on a Windows 7 computer?if you use windows 7, in some situations you will encounter an error that the system does not assign admin rights to store, use some programs on the hard drive system .... to fix this error you can refer to some answers below.
- How to grant Admin rights to a User in Win 10how to grant admin rights to a user in windows 10. to work effectively and ensure data on windows 10 computers, we often divide them into different users if the computer has 2 or more users. if you do not know how to grant admin rights to users in windows 10, please refer to the following tutorial!
- Microsoft urges Admin to patch PowerShell vulnerability on Windowsmicrosoft has just asked for it admins of organizations and businesses to immediately patch the vulnerability in powershell 7. the reason is that this vulnerability allows hackers to bypass windows defender application control (wdac) enforcement measures.
- How to assign admin rights to users in Ubuntuthis article will describe how to make a user admin via the graphical user interface and explain what commands you need to use on the command line to add a user to the sudo (authorized) user group.
- Mozilla is testing Firefox for Windows 8mozilla has just released a preview version of firefox for windows 8 for developers, although the complete version may only appear in january next year.
- Mozilla released Firefox 62.0.2 to fix the problem of corrupting the operating systemrecently, mozilla has released a firefox 62.0.2 update to fix serious bugs that could 'paralyze' the operating system discovered on firefox version 62 days ago.
- Firefox 57 Quantum is here, great Mozilla!on november 14, mozilla launched firefox 57 on windows, mac and linux. this is probably the biggest update in firefox's 13-year history.
- Firefox 16 just got stuck with a serious security bugmozilla must temporarily remove firefox 16.0 final from its website after detecting a serious security vulnerability in this version.
- New version of Firefox patched some additional security flawsmozilla has just made a second fix for firefox 16 after the technology industry discovered a series of security holes on this version on the official release date.