A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | Jun 24, 2021 |
| Mfsa2021 23 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 89.0 | Jun 2, 2021 | Jun 1, 2021 |
| Mfsa2021 24 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 78.11 | Jun 2, 2021 | Jun 1, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.11Upgrade to the latest version of Mozilla Thunderbird | Jun 4, 2021 | Jun 3, 2021 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 78.11.0-11.4.35.0.1.94.3 on Solaris 11.4Upgrade mail/thunderbird to version 78.11.0-11.4.35.0.1.94.3 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.11.0-11.4.35.0.1.94.3 on Solaris 11.4 | Jul 21, 2021 | Jun 24, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 24, 2021 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-otherUpgrade mozillafirefox-buildsymbolsUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-common | Jun 9, 2021 | Jun 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub