peter bassill · operator
$ cve CVE-2020-12388 JSON

CVE-2020-12388

10.0
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.44% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-05-26
Last modified2026-06-17

Affected (3)

VendorProduct
microsoftwindows
mozillafirefox
mozillafirefox esr

References

→ the Explorer  ·  watch your stack  ·  NVD