Description Preview
Overview
CVE-2021-29951 is a privilege management vulnerability (CWE-269) in Mozilla's Maintenance Service on Windows systems. The service incorrectly granted SERVICE_START access permissions to the BUILTIN\Users group, which in domain network environments allows standard users to control the service. This could be exploited by attackers to prevent browser updates by continuously stopping the service or potentially to leverage the exposed attack surface for other attacks. The vulnerability only affects Windows systems older than Windows 10 build 1709, with other operating systems remaining unaffected. This security issue demonstrates the importance of proper service permission configuration, as overly permissive settings can lead to security risks even in trusted applications.
Remediation
To address this vulnerability, users should update their Mozilla applications to the following versions or newer:
- Firefox: Update to version 87 or later
- Firefox ESR: Update to version 78.10.1 or later
- Thunderbird: Update to version 78.10.1 or later
System administrators should also consider:
- Reviewing service permissions on Windows systems, particularly in domain environments
- Implementing least privilege principles for all services
- Monitoring for unauthorized service control attempts
- Ensuring automatic updates are functioning properly after applying the fix
For users unable to update immediately, limiting domain user access to affected systems can help mitigate the risk until updates can be applied.
References
- Mozilla Foundation Security Advisory (MFSA2021-10): https://www.mozilla.org/security/advisories/mfsa2021-10/
- Mozilla Foundation Security Advisory (MFSA2021-18): https://www.mozilla.org/security/advisories/mfsa2021-18/
- Mozilla Foundation Security Advisory (MFSA2021-19): https://www.mozilla.org/security/advisories/mfsa2021-19/
- Mozilla Bugzilla Issue: https://bugzilla.mozilla.org/show_bug.cgi?id=1690062
- Common Weakness Enumeration (CWE-269): Improper Privilege Management
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Health Care & Social AssistanceHealth Care & Social Assistance
- Public AdministrationPublic Administration
- Transportation & WarehousingTransportation & Warehousing
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Retail TradeRetail Trade
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- UtilitiesUtilities
- Other Services (except Public Administration)Other Services (except Public Administration)
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- Wholesale TradeWholesale Trade
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- InformationInformation
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing