Junglewise Threat Intelligence

CVE-2019-11708: Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

CVE-2019-11708 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-05-23

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Insufficient vetting of parameters in the Prompt:Open IPC message between child and parent processes allows a compromised child process to force the non-sandboxed parent process to open arbitrary web content. When chained with other vulnerabilities, this enables a sandbox escape and remote code execution on the host system.

Affected products

  • Mozilla Firefox < 67.0.4
  • Mozilla Firefox ESR < 60.7.2
  • Mozilla Thunderbird < 60.7.2

Timeline

  • 2019-07-28: disclosed: Initial NVD analysis date
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-23: advisory: NVD publication date
  • 2019-12-09: other: Public exploit chain for Windows 64-bit reported

Related threats