CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-9680

CVSS 9.8v3.1pub. 2024-10-09upd. 2026-08-04

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

🤖 AI Analysis
How it works

The bug consists of improper memory management in the Animation timelines handling module — after an object is freed in memory, it is possible to reference it again (use-after-free), which leads to arbitrary code execution. An attacker can trigger the vulnerability remotely, without authentication and without user interaction, through a crafted website or email message rendered by the vulnerable application. Code execution occurs in the context of the content process.

Impact

An attacker can gain full control over the application's content process, which may lead to disclosure of confidential data, data modification, or application destabilization. In combination with other vulnerabilities, further system compromise is possible.

Mitigation & patch

Immediately update Mozilla Firefox to version 131.0.2 or later, Firefox ESR to version 128.3.1 or 115.16.1, Mozilla Thunderbird to version 131.0.1, 128.3.1 or 115.16.0 according to the update channel used in the organization.

Who is affected

Mozilla Firefox in versions below 131.0.2; Mozilla Firefox ESR in versions below 128.3.1 and below 115.16.1; Mozilla Thunderbird in versions below 131.0.1, below 128.3.1 and below 115.16.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Debian

    OS
    Debian
    11.0
  • Mozilla Firefox

    APP
    Mozilla
    128.1.0 – 128.3.1 (excl.)< 115.16.1< 131.0.2
  • Mozilla Thunderbird

    APP
    Mozilla
    131.0< 115.16.0128.0.1 – 128.3.1 (excl.)

CISA KEV — detailsi

Vendori
Mozilla
Producti
Firefox
Added to KEVi
October 15, 2024
Remediation deadline (US Federal)i
November 5, 2024(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 5 listopada 2024
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki