Mozilla patches a vulnerability in Firefox that helps hackers gain admin rights of Windows
This vulnerability resides in the Mozilla Maintenance Service, so if successfully exploited, hackers can gain admin rights of the system.
Mozilla Maintenance Service is an optional service of Firefox and Thunderbird that keeps application updates running in the background. It provides Firefox users with a seamless update experience, without the need to click the "Yes" option in Windows User Account Control (UAC) before updating their web browser or email client.
Mozilla has patched the privilege escalation vulnerability tracked under code CVE-2022-22753 in the just released Fifefox 97 update.
When successfully exploiting CVE-2022-22753 on unpatched computers, hackers can take over NT AUTHORITYSYSTEM, the highest control on Windows systems.
"A Time-of-Check Time-of-Use bug exists in the Mozilla Maintenance Service that can be abused to give users write permission to an arbitrary directory. This can be used to elevate access permissions. SYSTEM level," Mozilla shared. "This bug only affects Firefox on Windows. Other operating systems are not affected."
Mozilla also adds that Firefox 97 has resolved many of the memory-safe bugs found by the Mozilla community and developers in Firefox 96 and Firefox ESR 91.5.
Firefox 97 adds some new features and improvements
Besides bug fixes, the new Firefox update also brings a number of new features and improvements. The first is the new style scrollbars on Windows 11 and the next is an improvement in loading system fonts on macOS that makes opening and switching new tabs faster.
You should read it
- Discovering a new zero-day vulnerability in Steam, more than 100 million users may be affected
- New privilege escalation vulnerability called 'Dirty Pipe' is threatening all Linux distros
- Firefox 16 was released again after updating the vulnerability patch
- Firefox releases urgent update to patch zero-day vulnerability being exploited by hackers
- Mozilla released Firefox 62.0.2 to fix the problem of corrupting the operating system
- What to do when Firefox crashes?
- FireFox 54 version improves performance, speed, and security enhancement
- Firefox 58 and new features help improve performance
May be interested
- UEFI firmware from Microsoft, Intel, HP, Dell etc., can be at risk from nearly 20 different vulnerabilitiesbinarly, a security research company that specializes in dealing with firmware-related threats, revealed a very disturbing piece of information in a recent blog post.
- Detecting fake 2FA security apps that can steal bank accounts on Android phonesinternational security researchers have just discovered a dangerous fake two-factor authentication application on the android platform.
- Microsoft Outlook RCE Vulnerability Can Sell For $400,000if you discover a remote arbitrary code execution vulnerability affecting microsoft outlook, you can sell it for up to $ 400,000.
- Immediately patch CWP vulnerability that allows code execution as root on Linux serverssecurity researchers have discovered two new vulnerabilities affecting control web panel (cwp) software. hackers could chain these two vulnerabilities to gain remote code execution (rce) privileges as root on vulnerable linux servers.
- Microsoft 'turns the wheel' to bring the old Network Connections settings back to Windows 11obviously the network connections setting is easier to use than the advanced network settings in windows 11's settings.
- Google will automatically upgrade free G Suite users to Paid Workspace from May 1, 2022in 2020, g suite was renamed google workspace, part of google's massive refactoring of its work apps. many different subscription plans have been changed, and now google wants to remove the remaining free version of g suite.