ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Mozilla plugs critical Firefox zero-day used in targeted attacks

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-11707CVE-2019-11708

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11708
+1 in the same advisory: …11707
Sandbox Escape via IPC Parameter Flaw in Mozilla Firefox and Thunderbird

CVE-2019-11708 is an improper input-validation flaw (CWE-20) in the inter-process communication between Mozilla Firefox and Thunderbird's sandboxed child processes and the non-sandboxed parent process: parameters sent with the Prompt:Open IPC message are not sufficiently vetted. A compromised child process can therefore direct the non-sandboxed parent process to open attacker-chosen web content, escaping the sandbox; when chained with additional vulnerabilities this can result in arbitrary code execution on the user's computer. Anyone running Firefox < 67.0.4, Firefox ESR < 60.7.2, or Thunderbird < 60.7.2 is affected. The flaw was exploited as a zero-day in targeted attacks before the June 2019 fixes (per vendor advisories and news coverage), is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), and EPSS assigns a 55.9% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known, but the severity (CVSS 10.0), the sandbox scope change, and the KEV listing indicate high practical risk.

Do: Upgrade Firefox to 67.0.4 or later, Firefox ESR to 60.7.2 or later, and Thunderbird to 60.7.2 or later, per the vendor advisories and CISA KEV required action. Because the sandbox escape on its own only opens attacker-chosen content and must be chained with an additional vulnerability for code execution, also confirm that companion content-processing fixes released at the same time (per the 'second 0-day' coverage) are applied on the same hosts. Inventory endpoints for outdated Firefox/Thunderbird versions and prioritize patching internet-facing and targeted user populations.

10.0
group max
56% KEV
  • mozilla Firefox < 67.0.4
  • mozilla Firefox ESR < 60.7.2
  • mozilla Thunderbird < 60.7.2
mass≈250–300 million Firefox users plus tens of millions of Thunderbird users (estimated, order of magnitude)
Full article410 words · extracted from helpnetsecurity.com · click to collapse

A critical Firefox zero-day remote code execution vulnerability is being abused in targeted attacks in the wild, Mozilla has warned on Tuesday.

CVE-2019-11707

About the vulnerability (CVE-2019-11707)

Mozilla did not share many details about the flaw – it simply stated that it is a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, and that it can trigger an exploitable crash.

The flaw can be exploited to achieve arbitrary code execution. Depending on the privileges associated with user active at the time of the attack, an attacker could install programs, view, change, or delete data, or create new accounts with full user rights.

No details about the attacks have been released. Still, the fact that the credit for the discovery of CVE-2019-11707 goes to Coinbase Security and Samuel Groß of Google Project Zero, it seems likely that it the flaw is being exploited by attackers to target cryptocoin owners.

Start patching!

The vulnerability has been patched in Firefox 67.0.3 and Firefox ESR 60.7.1 for Windows, macOS and Linux. Firefox users should restart their browser to prompt an update.

This is the first time since late 2016 that a Firefox zero-day has been exploited in the wild. That flaw was exploited to de-anonymize users of the Tor Browser, which is based on Firefox ESR, Mozilla’s Firefox offering used by organizations that prefer stability over having the latest improvements as soon as they are made available.

UPDATE (June 20, 2019, 3:03 a.m. PT):

The Tor Project has released Tor Browser 8.5.2 (for desktops), with a fix for CVE-2019-11707.

Android users will have to wait for the Android release until the weekend. “In the meantime, Android users should use the safer or safest security levels,” the developers advised.

UPDATE (June 20, 2019, 4:40 a.m. PT):

Coinbase CISO Philip Martin says that the Firefox zero-day was used (unsuccessfully) against Coinbase employees, in conjunction with a separate 0-day Firefox sandbox escape. He also says that Coinbase is “not the only crypto org targeted in this campaign.”

1/ A little more context on the Firefox 0-day reports. On Monday, Coinbase detected & blocked an attempt by an attacker to leverage the reported 0-day, along with a separate 0-day firefox sandbox escape, to target Coinbase employees.

— Philip Martin (@SecurityGuyPhil) June 19, 2019

UPDATE (June 21, 2019, 5:00 a.m. PT):

Firefox users should upgrade again: Mozilla has fixed the 0-day Firefox sandbox escape (CVE-2019-11708) used in the Coinbase attack.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/06/19/firefox-cve-2019-11707/