Junglewise Threat Intelligence

CVE-2020-6820: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

CVE-2020-6820 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2021-11-03

Technologies: Mozilla Firefox ESR, Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A race condition in Mozilla Firefox and Thunderbird when handling a ReadableStream can lead to a use-after-free vulnerability. This flaw allows for unspecified impacts and has been observed in targeted attacks in the wild.

Affected products

  • Mozilla Firefox < 74.0.1
  • Mozilla Firefox ESR < 68.6.1
  • Mozilla Thunderbird < 68.7.0

Timeline

  • 2020-04-24: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog and vendor advisory.

Related threats