Executive brief
A race condition in the nsDocShell destructor in Mozilla Firefox and Thunderbird can lead to a use-after-free vulnerability. This flaw allows for potential remote code execution or unspecified impacts under certain conditions. Mozilla has acknowledged targeted attacks in the wild exploiting this vulnerability.
Affected products
- Mozilla Firefox < 74.0.1
- Mozilla Firefox ESR < 68.6.1
- Mozilla Thunderbird < 68.7.0
Timeline
- 2020-04-24: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-04-24: patched: Fixed in Firefox 74.0.1, Firefox ESR 68.6.1, and Thunderbird 68.7.0
- exploited: Mozilla reported awareness of targeted attacks in the wild.