ZeroHour
Security Affairspublished ()ingested @securityaffairs

Mozilla fixed a Firefox Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-11707

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11707
Type Confusion in Mozilla Firefox and Thunderbird JavaScript Engine

Mozilla Firefox and Thunderbird contain a type confusion flaw (CWE-843) in the JavaScript engine's Array.pop handling, which occurs when manipulating JavaScript objects and can lead to an exploitable crash. An attacker can trigger it by getting a user to load crafted web or email content that executes the malicious JavaScript, gaining a crash that is exploitable (typically escalating to arbitrary code execution in the browser or mail client context). All users of the affected Firefox and Thunderbird builds are exposed, since both products process untrusted web and HTML email content. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), indicating known in-the-wild exploitation, and it carries a high EPSS of 37.7% (98th percentile); no public proof-of-concept is cataloged and CVSS has not yet been scored.

Do: Apply updates per Mozilla's instructions, as required by the CISA KEV catalog: upgrade Firefox and Thunderbird to the latest supported releases and verify the installed version via the About dialog. Because the flaw dates to 2019, any fully updated auto-updating installation is already protected; audit for stale or unmanaged Firefox/Thunderbird deployments, and as an interim mitigation minimize JavaScript execution from untrusted web and email content.

8.838% KEV
  • Mozilla Firefox
  • Mozilla Thunderbird
masshundreds of millions of users in the potential base (Firefox install base plus tens of millions of Thunderbird installs), though currently unpatched installs…
Full article332 words · extracted from securityaffairs.com · click to collapse

Mozilla released security updates for Firefox that addressed a critical zero-day vulnerability exploited in targeted attacks in the wild.

Mozilla released security updates for its Firefox web browser that address a critical vulnerability that has been actively exploited in the wild.

The zero-day vulnerability, tracked as CVE-2019-11707, is a type confusion flaw in Array.pop. Mozilla has addressed it with the release of Firefox 67.0.3 and Firefox ESR 60.7.1.

“A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw.” reads the security advisory published by Mozilla.

mozilla firefox zero-day

The flaw was reported by Coinbase Security and Samuel Groß of Google Project Zero team. Samuel Groß explained that he reported the bug to Mozilla on April 15, 2019.

The researcher explained that the vulnerability could be used for remote code execution if chained with a separate sandbox escape issue.

The bug can be exploited for RCE but would then need a separate sandbox escape. However, most likely it can also be exploited for UXSS which might be enough depending on the attacker's goals. Looking forward to more details from @mozsec and @coinbase

— Samuel Groß (@5aelo) June 19, 2019

Mozilla confirmed that threat actors exploited the zero-day in targeted attacks in the wild, the organizations did not provide technical details of the issue.

The DHS’s Cybersecurity and Infrastructure Security Agency (CISA) also issued a short alert for the vulnerability in Mozilla.

“Mozilla has released security updates to address a vulnerability in Firefox and Firefox ESR. An attacker could exploit this vulnerability to take control of an affected system.” states the alert. “This vulnerability was detected in exploits in the wild.”

In 2016, security researchers found a malicious script that exploited another Firefox Zero-day to identify some users of the Tor anonymity network.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Mozilla Firefox zero-day, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/87318/hacking/firefox-zero-day-fixed.html