Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HMozilla Firefox
APPMozilla< 60.7.2< 67.0.4Mozilla Thunderbird
APPMozilla< 60.7.2
CISA KEV — detailsi
- Vendori
- Mozilla ↗
- Producti
- Firefox and Thunderbird
- Added to KEVi
- May 23, 2022
- Remediation deadline (US Federal)i
- June 13, 2022(overdue)
Apply updates per vendor instructions.
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
Related vulnerabilities
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 1...