EXPOSURES › CVE-2020-6820
CVE-2020-6820
HIGH ⌖ ON CISA KEV · EXPLOITEDFirefox and Thunderbird suffered a use-after-free vulnerability in their ReadableStream handling that was actively exploited in the wild.
A race condition in Firefox and Thunderbird allowed a use-after-free vulnerability when processing ReadableStreams, leading to unspecified impacts. DIB organizations must care because this flaw was in the KEV catalog, proving it was actively exploited in the wild, which could lead to arbitrary code execution or data theft. Organizations should ensure their browsers are patched to the latest version and consider using hardened, locked-down browser configurations to mitigate such risks.
Shame score — A use-after-free vulnerability in a widely used browser was actively exploited in the wild and added to the KEV catalog, indicating a significant security failure that could have led to data breaches or ransomware attacks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."