Firefox 74.0.1 addresses two zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-17026 | Type Confusion in Mozilla Firefox and Thunderbird IonMonkey JIT Compiler CVE-2019-17026 is a type confusion vulnerability (CWE-843) in the IonMonkey just-in-time (JIT) compiler of Mozilla's SpiderMonkey JavaScript engine, caused by incorrect alias information when setting array elements. It is triggered by attacker-controlled JavaScript, typically a malicious web page opened in Firefox or hostile scripted/remote content rendered by a Thunderbird message, which drives the miscompiled code path and corrupts memory in the JavaScript engine. As is typical for JIT type-confusion bugs in browsers, successful exploitation can lead to arbitrary code execution with the privileges of the signed-in user. Anyone running an affected Firefox or Thunderbird release is exposed, including enterprise deployments where Thunderbird renders untrusted email content. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation (EPSS 46.6%, 99th percentile), though no public proof-of-concept is known. Do: Upgrade Firefox to 71.0 or later (or ESR 68.3 or later) and Thunderbird to 68.3 or later, per Mozilla's December 2019 advisories, and verify installed versions in each product's About dialog. Because the flaw is on CISA's KEV list, federal agencies are required to apply the vendor updates promptly; there is no practical configuration mitigation beyond upgrading, though disabling the JIT via about:config is possible for users who cannot patch immediately. | 8.8 | 46% | KEV PoC |
| mass≈250 million users (Mozilla-reported Firefox monthly active users; all unpatched pre-December-2019 builds are vulnerable) | |
| CVE-2020-6820 +1 in the same advisory: …6819 | Use-after-free (race condition) in Mozilla Firefox and Thunderbird CVE-2020-6820 is a use-after-free vulnerability in Mozilla's Gecko-based products caused by a race condition (CWE-362) that occurs under certain conditions when handling a ReadableStream. It is triggered by attacker-controlled content, such as a crafted web page or email content processed by Thunderbird, that drives the timing race; the high attack complexity (AC:H in the CVSS vector) reflects the need to hit the right timing window. Successful exploitation corrupts freed memory and can compromise confidentiality, integrity, and availability (all rated high in the CVSS 8.1 score), typically enabling code execution within the affected application. All users of Firefox < 74.0.1, Firefox ESR < 68.6.1, and Thunderbird < 68.7.0 are affected — effectively the entire unpatched Firefox and Thunderbird installed base at the time of the emergency release. Mozilla confirmed targeted attacks in the wild abusing this flaw at disclosure, it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS currently assigns a 7.1% 30-day exploitation probability (94th percentile). Do: Upgrade Firefox to 74.0.1 or later, Firefox ESR to 68.6.1 or later, and Thunderbird to 68.7.0 or later, per the vendor advisories and CISA KEV required action. No workaround is documented, so inventory client fleets for versions below these releases and prioritize patching, especially for users who browse untrusted sites or open untrusted mail; disabling JavaScript can serve only as a temporary stopgap. | 8.1 | 7% | KEV |
| masshundreds of millions of users (Firefox's global monthly user base, plus tens of millions of Thunderbird installs) |
Full article274 words · extracted from securityaffairs.com · click to collapse

Mozilla releases Firefox version 74.0.1 to address two vulnerabilities exploited by threat actors in attacks in the wild, users should update their browsers asap.
Mozilla is urging users to install the latest version of its browser, Firefox 74.0.1, which addresses two bugs that are being exploited in the wild by threat actors.
The two vulnerabilities have been tracked as CVE-2020-6819 and CVE-2020-6820, both issues are user-after-free vulnerabilities that could be exploited to inject code in Firefox’s memory and execute it in the browser’s context.
Both issues are remote code execution vulnerabilities, Mozilla credited the researcher Francisco Alonso @revskills and the expert Javier Marcos of @JMPSecsecurity for the two issues.
https://twitter.com/revskills/status/1246141325680017415
Mozilla did not disclose technical details of the vulnerabilities.
According to Alonso, other browsers might have been impacted by both zero-day vulnerabilities. Below the descriptions the two flaws:
“Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw.” reads the advisory for the CVE-2020-6819 flaw.
“Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw.” reads the advisory for the CVE-2020-6820 flaw.
In January, Mozilla has released security updates for Firefox browser that addresses another zero-day vulnerability, tracked as CVE-2019-17026, that has been exploited in targeted attacks.
Researchers at Qihoo 360 and Japan CERT revealed that an APT group is exploiting two vulnerabilities, including the CVE-2019-17026 flaw, in attacks aimed at China and Japan.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Firefox, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/101045/security/firefox-74-0-1-two-zero-days.html