ZeroHour

CVE-2020-6819

KEV PoC mass

Race-Condition Use-After-Free in Mozilla Firefox and Thunderbird (CVE-2020-6819)

CISA: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

CVSS 3.1
8.1 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2020-6819 is a use-after-free memory-safety flaw in the Mozilla Firefox browsing engine that occurs while the nsDocShell destructor is running. It is triggered by a race condition: under certain conditions, concurrent activity during nsDocShell teardown frees an object that is still in use, corrupting memory. A remote attacker who wins this timing race can crash the application and potentially execute arbitrary code with the privileges of the signed-in user (CVSS 3.1: 8.1 High, network vector, high attack complexity). All Firefox releases before 74.0.1, Firefox ESR releases before 68.6.1, and Thunderbird releases before 68.7.0 are affected. Mozilla confirmed targeted attacks exploiting this flaw in the wild in March 2020, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03.

What to do: Update Firefox to 74.0.1 or later, Firefox ESR to 68.6.1 or later, and Thunderbird to 68.7.0 or later, applying updates per vendor instructions as required by CISA KEV. Audit your fleet for any Firefox below 74.0.1 (ESR below 68.6.1) and Thunderbird below 68.7.0, prioritizing systems used to browse untrusted web content. No workaround is listed in the available data, so prompt patching is the primary mitigation; note this was one of two critical Firefox zero-days fixed in the same 74.0.1/68.6.1 emergency release.

Affected
mozilla FirefoxAll versions prior to 74.0.1 (fixed in 74.0.1)
mozilla Firefox ESRAll versions prior to 68.6.1 (fixed in 68.6.1)
mozilla ThunderbirdAll versions prior to 68.7.0 (fixed in 68.7.0)
Estimated exposure
masshundreds of millions of users (roughly 200M+ Firefox users in early 2020, plus tens of millions of Thunderbird users; any user of an affected build is exposed… — No install counts are provided in the data, so this is estimated from Firefox's publicly reported user base of roughly 200-250 million monthly active users at the time of disclosure plus Thunderbird's large installed base, treating every…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CISA Known Exploited Vulnerability
Affected
Mozilla Firefox and Thunderbird
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news