Skip to content
COOEY

EXPOSURES › CVE-2019-17026

CVE-2019-17026

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-17026 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedrce

Mozilla Firefox and Thunderbird suffered a type confusion vulnerability in the IonMonkey JIT compiler that was actively exploited in the wild.

The vulnerability allowed attackers to execute arbitrary code by exploiting incorrect alias information in the IonMonkey JIT compiler when setting array elements. DIB organizations must ensure Firefox and Thunderbird are patched immediately, as this unpatched flaw was actively exploited in the wild, posing a significant risk to systems relying on these browsers for secure communications and data access.

Shame score — A known, actively exploited vulnerability in widely used software that was not patched before exploitation, demonstrating negligence in patch management and leaving systems exposed to remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
Standard CVE disclosure
cooey ↗ neutral +0.00
Neutral CVE disclosure
"Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.