CVE-2024-9680
Mozilla Firefox Use-After-Free Vulnerability
CVSS
9.8
Crítico
EPSS
23.2%
p98
KEV
SÍ
15 oct 2024
Exploit Today
79
0-100
Publicado: 9 oct 2024 · Última mod.: 4 ago 2026 · CWE-416
Producto
Mozilla / Firefox
Vulnerabilidad
Mozilla Firefox Use-After-Free Vulnerability
Añadido a KEV
15 oct 2024
Remediar antes de
5 nov 2024
Uso conocido en ransomware
Sí
Descripción resumida
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
Acción requerida
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notas
https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=1923344
- msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2024-51/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2024-52/
- bugs.freebsd.orghttps://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2024/10/msg00005.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2024/10/msg00006.html
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9680