Endpoint Vulnerability

Privilege escalation through file deletion by Maintenance Service updater

Description

Security researcher Holger Fuhrmannek reported an issue where the Mozilla Maintenance Service updater on Windows can delete arbitrary files because of its privileged system access. This file deletion can then potentially be used for further privilege escalation. This flaw requires users to execute a locally saved file in order for it to be triggered.

Affected Products

Firefox

References

CVE-2016-2809,