CVE-2024-9680
CRITICAL CISA KEV EPSS 98.1%
Published Oct 9, 20241y ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Published Oct 9, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Oct 15, 2024 1y ago
KEV Due Nov 5, 2024 602d overdue
Description
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
CISA Known Exploited Overdue 602d
- Added
- Oct 15, 2024
- Due
- Nov 5, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
EPSS Exploit Probability
98.1% percentile
Exploit & Patch Status
Actively Exploited (KEV)
Patch Available
Weaknesses 1
CWE-416 Use After Free Memory Safety
Affected Products 7
References 8
- bugs.freebsd.org https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992
- bugzilla.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1923344
- lists.debian.org https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2024/10/msg00006.html
- msrc.microsoft.com https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039
- cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9680
- mozilla.org https://www.mozilla.org/security/advisories/mfsa2024-51/
- mozilla.org https://www.mozilla.org/security/advisories/mfsa2024-52/
Remediation
- msrc.microsoft.com https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039