CVE-2020-6820
KEVmassUse-after-free (race condition) in Mozilla Firefox and Thunderbird
CISA: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
CVE-2020-6820 is a use-after-free vulnerability in Mozilla's Gecko-based products caused by a race condition (CWE-362) that occurs under certain conditions when handling a ReadableStream. It is triggered by attacker-controlled content, such as a crafted web page or email content processed by Thunderbird, that drives the timing race; the high attack complexity (AC:H in the CVSS vector) reflects the need to hit the right timing window. Successful exploitation corrupts freed memory and can compromise confidentiality, integrity, and availability (all rated high in the CVSS 8.1 score), typically enabling code execution within the affected application. All users of Firefox < 74.0.1, Firefox ESR < 68.6.1, and Thunderbird < 68.7.0 are affected — effectively the entire unpatched Firefox and Thunderbird installed base at the time of the emergency release. Mozilla confirmed targeted attacks in the wild abusing this flaw at disclosure, it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS currently assigns a 7.1% 30-day exploitation probability (94th percentile).
What to do: Upgrade Firefox to 74.0.1 or later, Firefox ESR to 68.6.1 or later, and Thunderbird to 68.7.0 or later, per the vendor advisories and CISA KEV required action. No workaround is documented, so inventory client fleets for versions below these releases and prioritize patching, especially for users who browse untrusted sites or open untrusted mail; disabling JavaScript can serve only as a temporary stopgap.
| mozilla firefox | < 74.0.1 |
| mozilla firefox_esr | < 68.6.1 |
| mozilla thunderbird | < 68.7.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
- Affected
- Mozilla Firefox and Thunderbird
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H