Executive brief
Mozilla Firefox and related products contain a use-after-free vulnerability in XSLT parameter processing. Removing an XSLT parameter during processing can lead to memory corruption, which may be exploited to achieve arbitrary code execution.
Affected products
- Mozilla Firefox < 97.0.2
- Mozilla Firefox ESR < 91.6.1
- Mozilla Firefox for Android < 97.3.0
- Mozilla Thunderbird < 91.6.2
- Mozilla Focus < 97.3.0
Timeline
- 2022-03-07: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2022-03-07: kev added
- 2022-03-07: exploited: Reports of attacks in the wild abusing this flaw.