CVE-2019-11765 Information

Description

A compromised content process could send a message to the parent process that would cause the ‘Click to Play’ permission prompt to be shown. However due to lack of validation from the parent process if the user accepted the permission request an attacker-controlled permission would be granted rather than the ‘Click to Play’ permission. This vulnerability affects Firefox 70.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1562582 https://www.mozilla.org/security/advisories/mfsa2019-34/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: