60
CVE-2020-12388
—CVSS 3.1
10.0 critical
EPSS
3%p85
Published
()
Modified
Description
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
- Vendors
- mozilla
- Products
- firefox, firefox esr
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H