A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esrUpgrade firefoxUpgrade thunderbird | Aug 22, 2024 | Sep 27, 2023 |
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade firefox-debuginfo | Nov 17, 2023 | Sep 27, 2023 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Feb 21, 2024 | Sep 27, 2023 |
| Mfsa2023 41 | — | Upgrade to Mozilla Firefox version 118.0 | Sep 27, 2023 | Sep 26, 2023 |
| Mfsa2023 42 | — | Upgrade to Mozilla Firefox ESR version 115.3 | Sep 27, 2023 | Sep 26, 2023 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 115.3 | Sep 27, 2023 | Sep 26, 2023 |
| Suse | — | Upgrade mozillafirefoxUpgrade mozillafirefox-branding-upstreamUpgrade mozillafirefox-translations-commonUpgrade mozillafirefox-develUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbirdUpgrade mozillafirefox-translations-other | Sep 28, 2023 | Sep 27, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub