#VU100951 Buffer overflow in Mozilla Firefox and Firefox ESR - CVE-2024-11691

 

#VU100951 Buffer overflow in Mozilla Firefox and Firefox ESR - CVE-2024-11691

Published: November 26, 2024 / Updated: December 16, 2024


Vulnerability identifier: #VU100951
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-11691
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in Apple GPU drivers. A remote attacker can trick the victim into visiting a specially crafted webpage, trigger memory corruption and execute arbitrary code on the target system.

Note, the vulnerability affects only installations on macOS operating system.


Remediation

Install updates from vendor's website.

External links