ZeroHour

CVE-2020-12388

CVSS 3.1
10.0 critical
EPSS
3%p85
Published
()
Modified
Description

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

Vendors
mozilla
Products
firefox, firefox esr
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news