Bonum Certa Men Certa

Mozilla Firefox 115.1 and 116 Released With Two Microsoft Windows-Only Security Issues Plugged

Reprinted with permission from Ryan

Firefox 115.1 and 116 Released With Two Windows-Only Security Issues Fixed



As usual, a Firefox release is out with serious security vulnerabilities inherited from Windows in addition to actual bugs in Firefox.



This is a common occurrence because Windows is badly designed and adds vulnerabilities to everything that runs on top of it.



CVE-2023-4052 creates a hazard using the NTFS version of symbolic links and a hole in Windows UAC (discretionary access controls).



CVE-2023-4054 is yet another Windows MetaFile-like bug that can be used to run malicious code without any warning.



CVE-2023-4052: File deletion and privilege escalation through Firefox uninstaller



Reporter ycdxsb Impact moderate



Description


The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user.
This bug only affects Firefox on Windows. Other operating systems are unaffected.



CVE-2023-4054: Lack of warning when opening appref-ms files



Reporter P Umar Farooq Impact moderate



Description


When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code.
This bug only affects Firefox on Windows. Other operating systems are unaffected.



Recent Techrights' Posts

IRC Proceedings: Thursday, October 30, 2025
IRC logs for Thursday, October 30, 2025
IRC Proceedings: Wednesday, October 29, 2025
IRC logs for Wednesday, October 29, 2025
Slopwatch: Brian Fagioli, Google News, and Other LLM Slopfarms
Why does Google News keep promoting these fake articles?
Links 29/10/2025: Amazon Kept "Data Center Water Use Secret", "Abuse of Power" Against Media
Links for the day
Gemini Links 29/10/2025: "My Hardware Specs" and "Goodbye Debian…"
Links for the day
EPO Cocainegate: Feedback and Clarifications
Part III will come out soon
Links 29/10/2025: "US Military Is Destroying the Planet Beyond Imagination" and Boat Strikes Deemed Unlawful
Links for the day
Quality Comes First (Techrights Search)
It's generally working already, but we wish to polish it some more
Techrights Party Countdown
Late next week we'll be holding a party near our home
European Parliament and Council Directive on Privacy is Vanishing
"edited / censored some time more recently"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 28, 2025
IRC logs for Tuesday, October 28, 2025
Slopwatch: The March of Slopfarms, From UbuntuPIT to Linux Journal and to Various Fake Sites Still Promoted by Google News
It's so worrying to see what the Web has become
Links 29/10/2025: CISA, Ukraine, and Amazon Problems
Links for the day
[Teaser] The EPO's Spokesperson, a Cocaine User, Fancies Young Women
How's that for "optics" in the EU and Europe's second-largest institution?