ZeroHour

CVE-2019-11707

KEVmass

Type Confusion in Mozilla Firefox and Thunderbird JavaScript Engine

CISA: Mozilla Firefox and Thunderbird Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
38%p98
Published
()
KEV added
AI analysis

Mozilla Firefox and Thunderbird contain a type confusion flaw (CWE-843) in the JavaScript engine's Array.pop handling, which occurs when manipulating JavaScript objects and can lead to an exploitable crash. An attacker can trigger it by getting a user to load crafted web or email content that executes the malicious JavaScript, gaining a crash that is exploitable (typically escalating to arbitrary code execution in the browser or mail client context). All users of the affected Firefox and Thunderbird builds are exposed, since both products process untrusted web and HTML email content. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), indicating known in-the-wild exploitation, and it carries a high EPSS of 37.7% (98th percentile); no public proof-of-concept is cataloged and CVSS has not yet been scored.

What to do: Apply updates per Mozilla's instructions, as required by the CISA KEV catalog: upgrade Firefox and Thunderbird to the latest supported releases and verify the installed version via the About dialog. Because the flaw dates to 2019, any fully updated auto-updating installation is already protected; audit for stale or unmanaged Firefox/Thunderbird deployments, and as an interim mitigation minimize JavaScript execution from untrusted web and email content.

Affected
Mozilla Firefox
Mozilla Thunderbird
Estimated exposure
masshundreds of millions of users in the potential base (Firefox install base plus tens of millions of Thunderbird installs), though currently unpatched installs… — Firefox has long held a multi-percent share of the global desktop browser market, implying an install base in the hundreds of millions, and Thunderbird adds tens of millions more installs; the share of users still on pre-patch builds is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CISA Known Exploited Vulnerability
Affected
Mozilla Firefox and Thunderbird
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news