Using SentinelOne, Application Management on Windows 10 and 11 computers. One Severity: Critical vulnerability is showing up as Firefox 46 46. CVE-2020-6831 applies only to versions of Firefox below version 68.8. The computer has Mozilla Firefox version 124.0.2 installed, per Programs and Features. I can’t find another version of Firefox installed on the computer. I can’t find any more copies of firefox.exe on the local drives of the computer. Any ideal where this Firefox 46 46 finding might be coming from? Do you know if SentinelOne is searching network shares as well as the local computer drive(s)?

2 Spice ups

Wonder if it is a stale entry in the registry? I have found a few issues like that are either a left over directory or Reg entry from an earlier install. Especially if it went from x86 to x64.

2 Spice ups

Thanks. Maybe that is it. I did search the registry and while the current version of Mozilla Firefox is located in Program Files, there are entries in Program Files (x86). I found firefox.exe under Program Files. I do not find it under Program Files (x86). Can you think of any other means to make sure that this is a false vulnerability?

1 Spice up

Can firefox install in the users app data folder like chrome does? I have had this problem for years…generally I remove the registry entry that shows the version and this goes away.

There is also the possibility that a user has a portable version of Firefox on a USB drive.

I’m assuming SentinelOne doesn’t give the file location?