Audit All Outdated Firefox Installations in Your Network
Mozilla new version for Firefox and Firefox ESR in light of a new 0-day vulnerability that was discovered in Firefox. CVE-2019-17026, a type confusion vulnerability, was fixed in these most recent versions preventing attackers from abusing the vulnerability to run code on client machines. So make sure to run our Firefox 72 audit. You can find more information about the Mozilla Firefox update in the Firefox 72 0-day blog post.
To find which machines still need to update their Mozilla Firefox version, you can use the color-coded audit below which shows exactly which machines have updated and which ones still need an update so all of your machines have an up-to-date Firefox installation. Go ahead and start running your Firefox 72 audit.
Firefox 71 and Firefox ESR 68.3 Audit Query
Select Top 1000000 tblAssets.AssetID,
tblAssets.AssetName,
tblAssets.Domain,
tsysAssetTypes.AssetTypename As AssetType,
tblAssets.Username,
tblAssets.Userdomain,
tsysAssetTypes.AssetTypeIcon10 As icon,
tblAssets.IPAddress,
tblSoftwareUni.softwareName As Software,
tblSoftware.softwareVersion As Version,
tblSoftwareUni.SoftwarePublisher As Publisher,
Case
When Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) > 72
And tblSoftwareUni.softwareName Like '%firefox%' Then 'Up to date'
tWhen Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) = 72 And
Cast(Replace(SubString(tblSoftware.softwareVersion, 4, CharIndex('.',
tblSoftware.softwareVersion)), '.', '') As INT) >= 1 And
tblSoftwareUni.softwareName Like '%firefox%' Then 'Up to date'
When Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) > 68
And tblSoftwareUni.softwareName Like '%firefox%ESR%' Then 'Up to date'
tWhen Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) = 68 And
Cast(Replace(SubString(tblSoftware.softwareVersion, 4, CharIndex('.',
tblSoftware.softwareVersion)), '.', '') As INT) >= 41 And
tblSoftwareUni.softwareName Like '%firefox%ESR%' Then 'Up to date'
Else 'Out of date'
End As [Patch Status],
tsysIPLocations.IPLocation,
tblAssetCustom.Manufacturer,
tblAssetCustom.Model,
tsysOS.OSname As OS,
tblAssets.SP,
tblAssets.Lastseen,
tblAssets.Lasttried,
tblSoftware.Lastchanged,
Case
When Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) > 72 Then '#d4f4be'
tWhen Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) = 72 And
Cast(Replace(SubString(tblSoftware.softwareVersion, 4, CharIndex('.',
tblSoftware.softwareVersion)), '.', '') As INT) >= 1 And
tblSoftwareUni.softwareName Like '%firefox%' Then '#d4f4be'
When Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) > 68 Then '#d4f4be'
tWhen Cast(SubString(tblSoftware.softwareVersion, 0, CharIndex('.',
tblSoftware.softwareVersion)) As INT) = 68 And
Cast(Replace(SubString(tblSoftware.softwareVersion, 4, CharIndex('.',
tblSoftware.softwareVersion)), '.', '') As INT) >= 41 And
tblSoftwareUni.softwareName Like '%firefox%ESR%'
t Then '#d4f4be'
Else '#ffadad'
End As backgroundcolor
From tblAssets
Inner Join tblAssetCustom On tblAssets.AssetID = tblAssetCustom.AssetID
Inner Join tsysAssetTypes On tsysAssetTypes.AssetType = tblAssets.Assettype
Inner Join tsysIPLocations On tsysIPLocations.LocationID =
tblAssets.LocationID
Inner Join tblState On tblState.State = tblAssetCustom.State
Inner Join tblSoftware On tblAssets.AssetID = tblSoftware.AssetID
Inner Join tblSoftwareUni On tblSoftwareUni.SoftID = tblSoftware.softID
Left Join tsysOS On tsysOS.OScode = tblAssets.OScode
Where tblSoftwareUni.softwareName Like '%Mozilla%firefox%' And
tblState.Statename = 'Active'