A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | Jun 24, 2021 |
| Mfsa2021 23 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 89.0 | Jun 2, 2021 | Jun 1, 2021 |
| Mfsa2021 24 | — | Upgrade to Mozilla Firefox ESR version 78.11Upgrade to the latest version of Mozilla Firefox | Jun 2, 2021 | Jun 1, 2021 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 78.11 | Jun 4, 2021 | Jun 3, 2021 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 78.11.0-11.4.35.0.1.94.3 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.11.0-11.4.35.0.1.94.3 on Solaris 11.4Upgrade mail/thunderbird to version 78.11.0-11.4.35.0.1.94.3 on Solaris 11.4 | Jul 21, 2021 | Jun 24, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 24, 2021 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-buildsymbolsUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-common | Jun 9, 2021 | Jun 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub