EXPOSURES › CVE-2019-17026
CVE-2019-17026
HIGH ⌖ ON CISA KEV · EXPLOITEDMozilla Firefox and Thunderbird suffered a type confusion vulnerability in the IonMonkey JIT compiler that was actively exploited in the wild.
The vulnerability allowed attackers to execute arbitrary code by exploiting incorrect alias information in the IonMonkey JIT compiler when setting array elements. DIB organizations must ensure Firefox and Thunderbird are patched immediately, as this unpatched flaw was actively exploited in the wild, posing a significant risk to systems relying on these browsers for secure communications and data access.
Shame score — A known, actively exploited vulnerability in widely used software that was not patched before exploitation, demonstrating negligence in patch management and leaving systems exposed to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
"Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements."