Skip to content
COOEY

EXPOSURES › CVE-2024-9680

CVE-2024-9680

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-9680 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Mozilla Firefox contains an actively exploited use-after-free vulnerability in animation timelines that allows remote code execution in the content process.

This use-after-free flaw in Firefox's animation engine enables attackers to execute arbitrary code remotely, directly linking to ransomware campaigns. DIB organizations must ensure their browsers are patched immediately, as unpatched instances provide a direct attack vector for lateral movement and data exfiltration. The vulnerability's presence in the KEV catalog confirms it is being actively weaponized in the wild.

Shame score — A critical use-after-free flaw in a widely deployed browser was actively exploited in the wild to deliver ransomware, demonstrating severe negligence in patch management and vulnerability disclosure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.