CVE-2019-11708
KEVmassSandbox Escape via IPC Parameter Flaw in Mozilla Firefox and Thunderbird
CISA: Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
CVE-2019-11708 is an improper input-validation flaw (CWE-20) in the inter-process communication between Mozilla Firefox and Thunderbird's sandboxed child processes and the non-sandboxed parent process: parameters sent with the Prompt:Open IPC message are not sufficiently vetted. A compromised child process can therefore direct the non-sandboxed parent process to open attacker-chosen web content, escaping the sandbox; when chained with additional vulnerabilities this can result in arbitrary code execution on the user's computer. Anyone running Firefox < 67.0.4, Firefox ESR < 60.7.2, or Thunderbird < 60.7.2 is affected. The flaw was exploited as a zero-day in targeted attacks before the June 2019 fixes (per vendor advisories and news coverage), is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), and EPSS assigns a 55.9% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known, but the severity (CVSS 10.0), the sandbox scope change, and the KEV listing indicate high practical risk.
What to do: Upgrade Firefox to 67.0.4 or later, Firefox ESR to 60.7.2 or later, and Thunderbird to 60.7.2 or later, per the vendor advisories and CISA KEV required action. Because the sandbox escape on its own only opens attacker-chosen content and must be chained with an additional vulnerability for code execution, also confirm that companion content-processing fixes released at the same time (per the 'second 0-day' coverage) are applied on the same hosts. Inventory endpoints for outdated Firefox/Thunderbird versions and prioritize patching internet-facing and targeted user populations.
| mozilla Firefox | < 67.0.4 |
| mozilla Firefox ESR | < 60.7.2 |
| mozilla Thunderbird | < 60.7.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
- Affected
- Mozilla Firefox and Thunderbird
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H