Threat Advisory

Mozilla Fixes critical Firefox zero-day Vulnerability Actively Exploited in attacks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical security vulnerability has been discovered in Firefox, Firefox Extended Support Release (ESR), and tracked as CVE-2024-9680, which has been actively exploited in the wild. This use-after-free bug in the Animation timeline component allows attackers to execute code in the content process, posing a significant risk to users. Exploitation methods may include targeting specific websites or drive-by download campaigns that deceive users into visiting malicious sites. Users are strongly advised to update to the latest versions of Firefox, Firefox ESR to mitigate the risk of active threats. Additionally, the Tor Browser has released an emergency update to address this vulnerability. Prompt action is crucial, as unpatched systems remain vulnerable to potential attacks leveraging this critical flaw.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical security vulnerability has been discovered in Firefox, Firefox Extended Support Release (ESR), and tracked as CVE-2024-9680, which has been actively exploited in the wild. This use-after-free bug in the Animation timeline component allows attackers to execute code in the content process, posing a significant risk to users. Exploitation methods may include targeting specific websites or drive-by download campaigns that deceive users into visiting malicious sites. Users are strongly advised to update to the latest versions of Firefox, Firefox ESR to mitigate the risk of active threats. Additionally, the Tor Browser has released an emergency update to address this vulnerability. Prompt action is crucial, as unpatched systems remain vulnerable to potential attacks leveraging this critical flaw.[emaillocker id="1283"]

 

  • CVE-2024-9680: It is a high-severity use-after-free vulnerability in Mozilla Firefox and Firefox ESR's Animation timeline component. It allows attackers to execute arbitrary code in the content process, posing significant risks to users. Exploitation of this vulnerability could lead to severe security breaches, including unauthorized access and data compromise.

RECOMMENDATION:

  • We strongly recommend you update Firefox to version 131.0.2, Firefox ESR to version 115.16.1 and 128.3.1.
  •  We strongly recommend you update Tor Browser to version 13.5.7.

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html

[/emaillocker]
crossmenu