Junglewise Threat Intelligence

CVE-2019-17026: Mozilla Firefox And Thunderbird Type Confusion Vulnerability

CVE-2019-17026 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Mozilla Firefox ESR, Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A type confusion vulnerability exists in the Mozilla IonMonkey JIT compiler due to incorrect alias information when setting array elements. This flaw can be exploited to execute arbitrary code or cause a denial of service when processing malicious web content.

Affected products

  • Mozilla Firefox < 72.0.1
  • Mozilla Firefox ESR < 68.4.1
  • Mozilla Thunderbird < 68.4.1

Timeline

  • 2020-01-08: patched: Fixed in Firefox 72.0.1, Firefox ESR 68.4.1, and Thunderbird 68.4.1
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: Publicly disclosed via NVD and CISA KEV catalog
  • 2021-11-03: exploited: CISA confirms targeted attacks in the wild abusing this flaw.

Related threats