ZeroHour
Security Affairspublished ()ingested @securityaffairs

Firefox 74.0.1 addresses two zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2020-6819CVE-2020-6820CVE-2019-17026

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-17026
Type Confusion in Mozilla Firefox and Thunderbird IonMonkey JIT Compiler

CVE-2019-17026 is a type confusion vulnerability (CWE-843) in the IonMonkey just-in-time (JIT) compiler of Mozilla's SpiderMonkey JavaScript engine, caused by incorrect alias information when setting array elements. It is triggered by attacker-controlled JavaScript, typically a malicious web page opened in Firefox or hostile scripted/remote content rendered by a Thunderbird message, which drives the miscompiled code path and corrupts memory in the JavaScript engine. As is typical for JIT type-confusion bugs in browsers, successful exploitation can lead to arbitrary code execution with the privileges of the signed-in user. Anyone running an affected Firefox or Thunderbird release is exposed, including enterprise deployments where Thunderbird renders untrusted email content. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation (EPSS 46.6%, 99th percentile), though no public proof-of-concept is known.

Do: Upgrade Firefox to 71.0 or later (or ESR 68.3 or later) and Thunderbird to 68.3 or later, per Mozilla's December 2019 advisories, and verify installed versions in each product's About dialog. Because the flaw is on CISA's KEV list, federal agencies are required to apply the vendor updates promptly; there is no practical configuration mitigation beyond upgrading, though disabling the JIT via about:config is possible for users who cannot patch immediately.

8.846% KEV PoC
  • Mozilla Firefox Releases prior to Mozilla's December 2019 fix releases (Firefox 71.0 / ESR 68.3 per Mozilla advisories; CISA source data does not list version ranges)
  • Mozilla Thunderbird Releases prior to Thunderbird 68.3 per Mozilla advisories (not listed in CISA source data)
mass≈250 million users (Mozilla-reported Firefox monthly active users; all unpatched pre-December-2019 builds are vulnerable)
CVE-2020-6820
+1 in the same advisory: …6819
Use-after-free (race condition) in Mozilla Firefox and Thunderbird

CVE-2020-6820 is a use-after-free vulnerability in Mozilla's Gecko-based products caused by a race condition (CWE-362) that occurs under certain conditions when handling a ReadableStream. It is triggered by attacker-controlled content, such as a crafted web page or email content processed by Thunderbird, that drives the timing race; the high attack complexity (AC:H in the CVSS vector) reflects the need to hit the right timing window. Successful exploitation corrupts freed memory and can compromise confidentiality, integrity, and availability (all rated high in the CVSS 8.1 score), typically enabling code execution within the affected application. All users of Firefox < 74.0.1, Firefox ESR < 68.6.1, and Thunderbird < 68.7.0 are affected — effectively the entire unpatched Firefox and Thunderbird installed base at the time of the emergency release. Mozilla confirmed targeted attacks in the wild abusing this flaw at disclosure, it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS currently assigns a 7.1% 30-day exploitation probability (94th percentile).

Do: Upgrade Firefox to 74.0.1 or later, Firefox ESR to 68.6.1 or later, and Thunderbird to 68.7.0 or later, per the vendor advisories and CISA KEV required action. No workaround is documented, so inventory client fleets for versions below these releases and prioritize patching, especially for users who browse untrusted sites or open untrusted mail; disabling JavaScript can serve only as a temporary stopgap.

8.17% KEV
  • mozilla firefox < 74.0.1
  • mozilla firefox_esr < 68.6.1
  • mozilla thunderbird < 68.7.0
masshundreds of millions of users (Firefox's global monthly user base, plus tens of millions of Thunderbird installs)
Full article274 words · extracted from securityaffairs.com · click to collapse

Mozilla releases Firefox version 74.0.1 to address two vulnerabilities exploited by threat actors in attacks in the wild, users should update their browsers asap.

Mozilla is urging users to install the latest version of its browser, Firefox 74.0.1, which addresses two bugs that are being exploited in the wild by threat actors.

The two vulnerabilities have been tracked as CVE-2020-6819 and CVE-2020-6820, both issues are user-after-free vulnerabilities that could be exploited to inject code in Firefox’s memory and execute it in the browser’s context.

Both issues are remote code execution vulnerabilities, Mozilla credited the researcher Francisco Alonso @revskills and the expert Javier Marcos of @JMPSecsecurity for the two issues.

https://twitter.com/revskills/status/1246141325680017415

Mozilla did not disclose technical details of the vulnerabilities.

According to Alonso, other browsers might have been impacted by both zero-day vulnerabilities. Below the descriptions the two flaws:

“Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw.” reads the advisory for the CVE-2020-6819 flaw.

“Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw.” reads the advisory for the CVE-2020-6820 flaw.

In January, Mozilla has released security updates for Firefox browser that addresses another zero-day vulnerability, tracked as CVE-2019-17026, that has been exploited in targeted attacks.

Researchers at Qihoo 360 and Japan CERT revealed that an APT group is exploiting two vulnerabilities, including the CVE-2019-17026 flaw, in attacks aimed at China and Japan.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Firefox, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/101045/security/firefox-74-0-1-two-zero-days.html