ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Firefox 67.0.4 Released — Mozilla Patches Second 0

criticalVulnerability exploited in the wildimportance 60CVE-2019-11708CVE-2019-11707

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11708
+1 in the same advisory: …11707
Sandbox Escape via IPC Parameter Flaw in Mozilla Firefox and Thunderbird

CVE-2019-11708 is an improper input-validation flaw (CWE-20) in the inter-process communication between Mozilla Firefox and Thunderbird's sandboxed child processes and the non-sandboxed parent process: parameters sent with the Prompt:Open IPC message are not sufficiently vetted. A compromised child process can therefore direct the non-sandboxed parent process to open attacker-chosen web content, escaping the sandbox; when chained with additional vulnerabilities this can result in arbitrary code execution on the user's computer. Anyone running Firefox < 67.0.4, Firefox ESR < 60.7.2, or Thunderbird < 60.7.2 is affected. The flaw was exploited as a zero-day in targeted attacks before the June 2019 fixes (per vendor advisories and news coverage), is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), and EPSS assigns a 55.9% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known, but the severity (CVSS 10.0), the sandbox scope change, and the KEV listing indicate high practical risk.

Do: Upgrade Firefox to 67.0.4 or later, Firefox ESR to 60.7.2 or later, and Thunderbird to 60.7.2 or later, per the vendor advisories and CISA KEV required action. Because the sandbox escape on its own only opens attacker-chosen content and must be chained with an additional vulnerability for code execution, also confirm that companion content-processing fixes released at the same time (per the 'second 0-day' coverage) are applied on the same hosts. Inventory endpoints for outdated Firefox/Thunderbird versions and prioritize patching internet-facing and targeted user populations.

10.0
group max
56% KEV
  • mozilla Firefox < 67.0.4
  • mozilla Firefox ESR < 60.7.2
  • mozilla Thunderbird < 60.7.2
mass≈250–300 million Firefox users plus tens of millions of Thunderbird users (estimated, order of magnitude)
Full article440 words · extracted from thehackernews.com · click to collapse

The Hacker NewsJun 21, 2019

Okay, folks, it's time to update your Firefox web browser once again—yes, for the second time this week.

After patching a critical actively-exploited vulnerability in Firefox 67.0.3 earlier this week, Mozilla is now warning millions of its users about a second zero-day vulnerability that attackers have been found exploiting in the wild.

The newly patched issue (CVE-2019-11708) is a "sandbox escape" vulnerability, which if chained together with the previously patched "type confusion" bug (CVE-2019-11707), allows a remote attacker to execute arbitrary code on victims' computers just by convincing them into visiting a malicious website.

Browser sandboxing is a security mechanism that keeps third-party processes isolated and confined to the browser, preventing them from damaging other sensitive parts of a computer's operating system.

"Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process," the advisory explains.

Firefox 0-Days Found Exploited in the Wild

Mozilla has already been aware of the first issue since April when a Google Project Zero researcher reported it to the company, but it learned about the second issue and attacks in the wild just last week when attackers started exploiting both the flaws together to target employees from Coinbase platform and users of other cryptocurrency firms.

Just yesterday, macOS security expert Patrick Wardle also published a report revealing that a separate campaign against cryptocurrency users is also using same Firefox 0-days to install a macOS malware on targeted computers.

At this moment it's not clear if attackers independently discovered the first vulnerability just in time when it was already reported to Mozilla or gained classified bug-report information through another way.

Install Firefox Patches to Prevent Cyber Attacks

Anyway, the company has now released Firefox version 67.0.4 and Firefox ESR 60.7.2 that address both the issues, preventing attackers from remotely taking control over your systems.

Though Firefox installs latest available updates automatically, users are still advised to ensure they are running Firefox 67.0.4 or later.

Besides this, just like the patch for the previous issue, it is also expected that the Tor Project will once again release a new version of its privacy browser very soon to patch the second bug as well.

Important Update (21/06/2019) ➤ The Tor Project on Friday also released second update (Tor Browser 8.5.3) for its privacy web-browser this week that patches the second vulnerability Firefox patched yesterday.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/06/firefox-0day-vulnerability.html