Executive brief
Insufficient vetting of parameters in the Prompt:Open IPC message between child and parent processes allows a compromised child process to force the non-sandboxed parent process to open arbitrary web content. When chained with other vulnerabilities, this enables a sandbox escape and remote code execution on the host system.
Affected products
- Mozilla Firefox < 67.0.4
- Mozilla Firefox ESR < 60.7.2
- Mozilla Thunderbird < 60.7.2
Timeline
- 2019-07-28: disclosed: Initial NVD analysis date
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-23: advisory: NVD publication date
- 2019-12-09: other: Public exploit chain for Windows 64-bit reported