CVE-2019-11708 KEV EXPLOIT
10.0
CRITICAL · CVSS 3.1 · EPSS 55.9% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-13.
Description
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 55.87% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2022-06-13 |
| Public exploit | yes |
| Published | 2019-07-23 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability |
|---|---|
| Added | 2022-05-23 |
| Due | 2022-06-13 |
| Vendor / product | Mozilla / Firefox and Thunderbird |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack | 2019-12-07 |
References
- http://packetstormsecurity.com/files/155592/Mozilla-Firefox-Windows-64-Bit-Chain-Exploit.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=1559858
- https://security.gentoo.org/glsa/201908-12
- https://www.mozilla.org/security/advisories/mfsa2019-19/
- https://www.mozilla.org/security/advisories/mfsa2019-20/
- http://packetstormsecurity.com/files/155592/Mozilla-Firefox-Windows-64-Bit-Chain-Exploit.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=1559858
- https://security.gentoo.org/glsa/201908-12
- https://www.mozilla.org/security/advisories/mfsa2019-19/
- https://www.mozilla.org/security/advisories/mfsa2019-20/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11708
→ the Explorer · watch your stack · NVD