Security features bypass in Mozilla Firefox and Firefox ESR - CVE-2024-2605

 

Security features bypass in Mozilla Firefox and Firefox ESR - CVE-2024-2605

Published: March 19, 2024 / Updated: March 19, 2024


Vulnerability identifier: #VU87629
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2605
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in the Windows Error Reporter implementation. A remote attacker can trick the victim to visit a specially crafted website and run arbitrary code on the system escaping the sandbox.

Note, the vulnerability affects Windows installations only.


Affected software

Mozilla Firefox
Firefox ESR
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
Fedora
Slackware Linux
SUSE Package Hub 15
openSUSE Leap
Anolis OS
Oracle Solaris
Mozilla Thunderbird
seamonkey
mozilla-thunderbird
mozilla-firefox
thunderbird
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaThunderbird
MozillaThunderbird-debuginfo
firefox
firefox-wayland
firefox-x11

How to mitigate CVE-2024-2605

Install updates from vendor's website.

Mozilla Firefox - update to 124.0
Firefox ESR - update to 115.9.0
Mozilla Thunderbird - update to 115.9.0
seamonkey - update to 2.53.18.2
seamonkey - addressed in versions 2.53.18.2-1.el7, 2.53.18.2-1.el8, 2.53.18.2-1.fc38, 2.53.18.2-1.fc39, 2.53.18.2-1.fc40
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
mozilla-thunderbird - update to 115.9.0
mozilla-firefox - update to 115.9.0esr
thunderbird - addressed in versions 115.9.0-1.fc38, 115.9.0-1.fc39, 115.9.0-1.fc40
MozillaThunderbird-debugsource - update to 115.9.0-150200.8.154.1
MozillaThunderbird-translations-common - update to 115.9.0-150200.8.154.1
MozillaThunderbird-translations-other - update to 115.9.0-150200.8.154.1
MozillaThunderbird - update to 115.9.0-150200.8.154.1
MozillaThunderbird-debuginfo - update to 115.9.0-150200.8.154.1
firefox - update to 115.13.0-1
firefox-wayland - update to 115.13.0-1
firefox-x11 - update to 115.13.0-1

External References

Related Security Bulletins