ZeroHour

CVE-2016-9079

KEV PoC ×3mass

Use-After-Free in Mozilla Firefox and Tor Browser SVG Animation Exploited in the Wild

CISA: Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

CVSS 3.1
7.5 high
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2016-9079 is a use-after-free flaw (CWE-416) in the SVG Animation component of Mozilla's Gecko engine, affecting Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1, as well as the Firefox-ESR-based Tor Browser and distro-packaged builds on Debian and Red Hat Enterprise Linux. It is triggered when the browser renders SVG content with animations, typically by loading a crafted web page, causing a freed SVG animation object to be reused and corrupting memory. A successful attack can lead to arbitrary code execution in the browser context or disclosure of sensitive memory contents; the assigned CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects network-triggered memory corruption with high confidentiality impact and no privileges required. The in-the-wild exploit observed at disclosure targeted Firefox and Tor Browser users on Windows. The flaw has public PoC exploits, carries an EPSS 30-day exploitation probability of 87.4% (100th percentile), and was added to the CISA KEV catalog on 2023-06-22 with a required action to apply vendor updates.

What to do: Upgrade Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later, and install the corresponding patched Tor Browser build; users on Windows were the observed in-the-wild targets, so prioritize those hosts. On Debian and Red Hat Enterprise Linux, apply the vendor's updated firefox/thunderbird/tor packages per their advisories, consistent with the CISA KEV required action. As an interim mitigation, restrict loading of untrusted web content with animated SVG and verify no machines in the environment are still running Firefox versions older than 50.0.2.

Affected
mozilla Firefox< 50.0.2
mozilla Firefox ESR< 45.5.1
mozilla Thunderbird< 45.5.1
torproject tor (Tor Browser, Firefox ESR-based)builds based on Firefox ESR < 45.5.1; exact Tor Browser version not specified in source data
Debian Linux (firefox, thunderbird, tor packages)
redhat Red Hat Enterprise Linux (Server, Server AUS, Server EUS, Desktop, Workstation; firefox/thunderbird packages)
Estimated exposure
mass~200-300 million Firefox users/install base at the time of disclosure (late 2016), plus roughly 1-2 million Tor Browser daily users (Windows-targeted… — Firefox had a user base in the hundreds of millions when this was disclosed in November 2016 and Tor Browser had on the order of 1-2 million daily users, so population-level browser market-base figures are used rather than exposed-asset…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

CISA Known Exploited Vulnerability
Affected
Mozilla Firefox, Firefox ESR, and Thunderbird
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
debianredhatmozillatorproject
Products
debian linux, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, thunderbird, firefox, tor
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news