Sunday, April 27, 2025
HomeHacksMozilla Firefox Fixed More than 25 Critical and High Critical Vulnerabilities in...

Mozilla Firefox Fixed More than 25 Critical and High Critical Vulnerabilities in Firefox 54.0 Release – Its time to Update your Firefox

Published on

SIEM as a Service

Follow Us on Google News

Firefox has between 9% and 16% of worldwide usage as a “desktop” browser and 2nd Most Popular Web Browser in the Globe. The latest version of the “Firefox 54.0” Released with 32 Patched Critical and High  Critical Vulnerabilities and some of the Vulnerabilities Leads to Crash the Browser.

This vulnerability was Reported by Many individual Security Researchers and some of the Vulnerabilities Discovered by Mozilla developers and community.

Firefox 54.0

Mozilla is calling Firefox 54.0 “the best Firefox ever,” since new version Release with Futures of multiple content processes, a UI process, and a GPU acceleration process.

- Advertisement - Google News

This New version contains  multiple content processes will improve stability and performance (one bad tab won’t slow down the rest of your computer)

  • New futures added including, Simplified the download button and download status panel and Added support for multiple content processes.
  • New Version changes, Moved the mobile bookmarks folder to the main bookmarks menu for easier access

To Run even complex sites faster, Mozilla changed multiples Operating system Processing.

The old Firefox used a single process to run all the tabs in a browser. Modern browsers split the load into several independent processes. 

Resulted in a crash Browser

These Vulnerabilities lead to Crash the Entire Browser.

CVE-2017-5472:

A Frame loader Vulnerabilities has leads to Crash the Browser while regenerating CSS layout when access nonexisting Tree Node.

CVE-2017-7749:

A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash.

CVE-2017-7750:

This Vulnerability also leads to Crash, During Video Control Operation old window Referred by <Track> element when old window replaced by Document object model.

CVE-2017-7751

A use-after-free vulnerability with content viewer-listeners that results in a potentially exploitable crash.

CVE-2017-7756

logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash.

CVE-2017-7757

IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed.

Also Read Fast and Complete SSL Scanner to Find Mis-configurations affecting TLS/SSL Severs -A Detailed Analysis

Privilege Escalation 

These are critical privilege escalation vulnerabilities that have been fixed by Mozilla.

CVE-2017-7760

This Vulnerability indicates manipulation of files in the installation directory and privilege escalation by manipulating the Mozilla Maintenance Service. This Vulnerability affected only Windows OS since this need local privilege to access.

CVE-2017-7761:

This High critical vulnerability leads to deleted the files and escalates the privilege using helper.exe Mozilla maintenance service.

CVE-2017-7766:

An attack using manipulation of updater.ini contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution

CVE-2017-7767

To overwrite arbitrary files with junk data using the Mozilla Windows Updater using  Maintenance invoked by an unprivileged user which only affected by Windows user.

CVE-2017-7768

Maintenance Service executes with privileged access, bypassing system protections against unprivileged by the user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater.

Also read Millions of time Downloaded dangerous malware app

All the fixed  Vulnerabilities are Explained in Firefox Blog

Download New Version

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Gain Legends International Suffers Security Breach – Customers Data Stolen

Gain Legends International, a prominent name in sports, entertainment, and venue management, has confirmed...

Over 17,000 Fortinet Devices Hacked Using Symbolic Link Exploit

A major cyberattack has compromised more than 17,000 Fortinet devices globally, exploiting a sophisticated...

Hacktivist Group Becomes More Sophisticated, Targets Critical Infrastructure to Deploy Ransomware

A recent report by Cyble has shed light on the evolving tactics of hacktivist...