If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefox-esralpine-linux-upgrade-thunderbirdalpine-linux-upgrade-firefox | Aug 22, 2024 | Sep 27, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bin | Feb 21, 2024 | Sep 27, 2023 | |
| Mfsa2023 41 | mozilla-firefox-upgrade-118_0 | Sep 27, 2023 | Sep 26, 2023 | |
| Mfsa2023 42 | mozilla-firefox-esr-upgrade-115_3 | Sep 27, 2023 | Sep 26, 2023 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-115_3 | Sep 27, 2023 | Sep 26, 2023 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Sep 28, 2023 | Sep 27, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub