EXPOSURES › CVE-2020-6819
CVE-2020-6819
HIGH ⌖ ON CISA KEV · EXPLOITEDMozilla Firefox and Thunderbird suffered a use-after-free vulnerability that was actively exploited in the wild.
A race condition in Firefox and Thunderbird allowed attackers to execute arbitrary code via a use-after-free bug, which was later added to CISA's KEV catalog. DIB organizations must ensure their browsers are patched immediately, as unpatched versions can lead to remote code execution and compromise of sensitive data. This failure highlights the risk of relying on software with known, unpatched vulnerabilities that are actively exploited.
Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, indicating a significant security failure that could have led to data breaches or system compromises if not patched.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."