CVE-2024-9680
Mozilla Firefox Use-After-Free Vulnerability
CVSS
9.8
Critical
EPSS
23.2%
p98
KEV
YES
Oct 15, 2024
Exploit Today
79
0-100
Published: Oct 9, 2024 · Last modified: Aug 4, 2026 · CWE-416
Product
Mozilla / Firefox
Vulnerability
Mozilla Firefox Use-After-Free Vulnerability
Added to KEV
Oct 15, 2024
Remediate by
Nov 5, 2024
Known ransomware use
Yes
Summary description
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=1923344
- msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2024-51/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2024-52/
- bugs.freebsd.orghttps://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2024/10/msg00005.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2024/10/msg00006.html
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9680