CVE-2020-6819
KEV PoC massRace-Condition Use-After-Free in Mozilla Firefox and Thunderbird (CVE-2020-6819)
CISA: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
CVE-2020-6819 is a use-after-free memory-safety flaw in the Mozilla Firefox browsing engine that occurs while the nsDocShell destructor is running. It is triggered by a race condition: under certain conditions, concurrent activity during nsDocShell teardown frees an object that is still in use, corrupting memory. A remote attacker who wins this timing race can crash the application and potentially execute arbitrary code with the privileges of the signed-in user (CVSS 3.1: 8.1 High, network vector, high attack complexity). All Firefox releases before 74.0.1, Firefox ESR releases before 68.6.1, and Thunderbird releases before 68.7.0 are affected. Mozilla confirmed targeted attacks exploiting this flaw in the wild in March 2020, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03.
What to do: Update Firefox to 74.0.1 or later, Firefox ESR to 68.6.1 or later, and Thunderbird to 68.7.0 or later, applying updates per vendor instructions as required by CISA KEV. Audit your fleet for any Firefox below 74.0.1 (ESR below 68.6.1) and Thunderbird below 68.7.0, prioritizing systems used to browse untrusted web content. No workaround is listed in the available data, so prompt patching is the primary mitigation; note this was one of two critical Firefox zero-days fixed in the same 74.0.1/68.6.1 emergency release.
| mozilla Firefox | All versions prior to 74.0.1 (fixed in 74.0.1) |
| mozilla Firefox ESR | All versions prior to 68.6.1 (fixed in 68.6.1) |
| mozilla Thunderbird | All versions prior to 68.7.0 (fixed in 68.7.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
- Affected
- Mozilla Firefox and Thunderbird
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H