CVE-2019-11707
KEVmassType Confusion in Mozilla Firefox and Thunderbird JavaScript Engine
CISA: Mozilla Firefox and Thunderbird Type Confusion Vulnerability
Mozilla Firefox and Thunderbird contain a type confusion flaw (CWE-843) in the JavaScript engine's Array.pop handling, which occurs when manipulating JavaScript objects and can lead to an exploitable crash. An attacker can trigger it by getting a user to load crafted web or email content that executes the malicious JavaScript, gaining a crash that is exploitable (typically escalating to arbitrary code execution in the browser or mail client context). All users of the affected Firefox and Thunderbird builds are exposed, since both products process untrusted web and HTML email content. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), indicating known in-the-wild exploitation, and it carries a high EPSS of 37.7% (98th percentile); no public proof-of-concept is cataloged and CVSS has not yet been scored.
What to do: Apply updates per Mozilla's instructions, as required by the CISA KEV catalog: upgrade Firefox and Thunderbird to the latest supported releases and verify the installed version via the About dialog. Because the flaw dates to 2019, any fully updated auto-updating installation is already protected; audit for stale or unmanaged Firefox/Thunderbird deployments, and as an interim mitigation minimize JavaScript execution from untrusted web and email content.
| Mozilla Firefox | — |
| Mozilla Thunderbird | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
- Affected
- Mozilla Firefox and Thunderbird
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H