ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Firefox Releases Critical Patch Update to Stop Ongoing Zero

criticalVulnerability exploited in the wildimportance 60CVE-2019-11707

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11707
Type Confusion in Mozilla Firefox and Thunderbird JavaScript Engine

Mozilla Firefox and Thunderbird contain a type confusion flaw (CWE-843) in the JavaScript engine's Array.pop handling, which occurs when manipulating JavaScript objects and can lead to an exploitable crash. An attacker can trigger it by getting a user to load crafted web or email content that executes the malicious JavaScript, gaining a crash that is exploitable (typically escalating to arbitrary code execution in the browser or mail client context). All users of the affected Firefox and Thunderbird builds are exposed, since both products process untrusted web and HTML email content. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), indicating known in-the-wild exploitation, and it carries a high EPSS of 37.7% (98th percentile); no public proof-of-concept is cataloged and CVSS has not yet been scored.

Do: Apply updates per Mozilla's instructions, as required by the CISA KEV catalog: upgrade Firefox and Thunderbird to the latest supported releases and verify the installed version via the About dialog. Because the flaw dates to 2019, any fully updated auto-updating installation is already protected; audit for stale or unmanaged Firefox/Thunderbird deployments, and as an interim mitigation minimize JavaScript execution from untrusted web and email content.

8.838% KEV
  • Mozilla Firefox
  • Mozilla Thunderbird
masshundreds of millions of users in the potential base (Firefox install base plus tens of millions of Thunderbird installs), though currently unpatched installs…
Full article381 words · extracted from thehackernews.com · click to collapse

The Hacker NewsJun 19, 2019

Important Update [21 June 2019]Mozilla on Thursday released another update Firefox version 67.0.4 to patch a second zero-day vulnerability.

If you use the Firefox web browser, you need to update it right now.

Mozilla earlier today released Firefox 67.0.3 and Firefox ESR 60.7.1 versions to patch a critical zero-day vulnerability in the browsing software that hackers have been found exploiting in the wild.

Discovered and reported by Samuel Groß, a cybersecurity researcher at Google Project Zero, the vulnerability could allow attackers to remotely execute arbitrary code on machines running vulnerable Firefox versions and take full control of them.

The vulnerability, identified as CVE-2019-11707, affects anyone who uses Firefox on desktop (Windows, macOS, and Linux) — whereas, Firefox for Android, iOS, and Amazon Fire TV are not affected.

According to an advisory, the flaw has been labeled as a type confusion vulnerability in Firefox that can result in an exploitable crash due to issues in Array.pop which can occur when manipulating JavaScript objects.

At the time of writing, neither the researcher nor Mozilla has yet released any further technical details or proof-of-concept for this flaw.

Through Firefox automatically installs latest updates and activate new version after a restart, users are still advised to ensure they are running the latest Firefox 67.0.3 and Firefox (Extended Support Release) 60.7.1 or later.

Update

The researcher later today shared a few more details about the flaw with The Hacker News, saying the reported flaw primarily leads to Universal Cross-site Scripting (UXSS) attacks, but if combined with a sandbox escape issue, it could also allow attackers to execute arbitrary code remotely on a targeted systems.

"I don't have any insights into the active exploitation part. I found and then reported the bug on April 15. The first public fix then landed about a week ago (sec fixes are held back until close to the next release):" Groß said on Twitter.

"The bug can be exploited for RCE but would then need a separate sandbox escape. However, most likely it can also be exploited for UXSS which might be enough depending on the attacker's goals."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/06/mozilla-firefox-patch-update.html