EXPOSURES › CVE-2019-11707
CVE-2019-11707
HIGH ⌖ ON CISA KEV · EXPLOITEDA type confusion vulnerability in Firefox and Thunderbird's Array.pop function allowed an exploitable crash, listed in CISA's KEV catalog.
This type confusion bug in Mozilla's JavaScript object handling could be exploited to crash the browser, and its inclusion in CISA's KEV catalog confirms active exploitation in the wild. For DIB organizations, this highlights the risk of relying on widely deployed software with known, unpatched vulnerabilities that attackers actively target. The takeaway is to ensure all browsers and email clients are patched to the latest versions and to monitor for exploitation attempts.
Shame score — The vulnerability was actively exploited in the wild (KEV) and affected widely used software, indicating a failure to patch known issues before they were weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.