Skip to content
COOEY

EXPOSURES › CVE-2020-6820

CVE-2020-6820

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-6820 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatched

Firefox and Thunderbird suffered a use-after-free vulnerability in their ReadableStream handling that was actively exploited in the wild.

A race condition in Firefox and Thunderbird allowed a use-after-free vulnerability when processing ReadableStreams, leading to unspecified impacts. DIB organizations must care because this flaw was in the KEV catalog, proving it was actively exploited in the wild, which could lead to arbitrary code execution or data theft. Organizations should ensure their browsers are patched to the latest version and consider using hardened, locked-down browser configurations to mitigate such risks.

Shame score — A use-after-free vulnerability in a widely used browser was actively exploited in the wild and added to the KEV catalog, indicating a significant security failure that could have led to data breaches or ransomware attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
Standard CVE disclosure
cooey ↗ neutral +0.00
Standard CVE disclosure
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.