Skip to content
COOEY

EXPOSURES › CVE-2019-11708

CVE-2019-11708

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11708 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Mozilla Firefox and Thunderbird suffered a sandbox escape vulnerability allowing remote code execution, which was actively exploited in the wild.

A sandbox escape flaw in Firefox and Thunderbird enabled attackers to execute arbitrary code remotely, bypassing critical security boundaries. DIB organizations must ensure these browsers are patched immediately, as the vulnerability was actively exploited in the wild and linked to ransomware campaigns. Failure to patch exposes systems to full system compromise and violates CMMC/NIST 800-171 requirements for timely patch management.

Shame score — A sandbox escape vulnerability in a widely used browser was actively exploited in the wild, indicating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.