ZeroHour

CVE-2020-6820

KEVmass

Use-after-free (race condition) in Mozilla Firefox and Thunderbird

CISA: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

CVSS 3.1
8.1 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2020-6820 is a use-after-free vulnerability in Mozilla's Gecko-based products caused by a race condition (CWE-362) that occurs under certain conditions when handling a ReadableStream. It is triggered by attacker-controlled content, such as a crafted web page or email content processed by Thunderbird, that drives the timing race; the high attack complexity (AC:H in the CVSS vector) reflects the need to hit the right timing window. Successful exploitation corrupts freed memory and can compromise confidentiality, integrity, and availability (all rated high in the CVSS 8.1 score), typically enabling code execution within the affected application. All users of Firefox < 74.0.1, Firefox ESR < 68.6.1, and Thunderbird < 68.7.0 are affected — effectively the entire unpatched Firefox and Thunderbird installed base at the time of the emergency release. Mozilla confirmed targeted attacks in the wild abusing this flaw at disclosure, it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS currently assigns a 7.1% 30-day exploitation probability (94th percentile).

What to do: Upgrade Firefox to 74.0.1 or later, Firefox ESR to 68.6.1 or later, and Thunderbird to 68.7.0 or later, per the vendor advisories and CISA KEV required action. No workaround is documented, so inventory client fleets for versions below these releases and prioritize patching, especially for users who browse untrusted sites or open untrusted mail; disabling JavaScript can serve only as a temporary stopgap.

Affected
mozilla firefox< 74.0.1
mozilla firefox_esr< 68.6.1
mozilla thunderbird< 68.7.0
Estimated exposure
masshundreds of millions of users (Firefox's global monthly user base, plus tens of millions of Thunderbird installs) — Firefox was one of the world's most widely deployed browsers with roughly 250M+ monthly active users and Thunderbird has a multi-million-user installed base, so any deployment running versions below the fixed releases is exposed; the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CISA Known Exploited Vulnerability
Affected
Mozilla Firefox and Thunderbird
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news