CVE-2019-11708

NVD Published Date: July 23, 2019 at 02:15 PM
NVD Last Modified: July 02, 2024 at 05:02 PM
Download Patch
Vulnerability ID
CVE-2019-11708
Severity
CRITICAL
Severity Score
10.0
Summary
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
Mitigation and Patches
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE ID
CWE-20

Recent Publish

KB5002642

KB5002648

CVE-2020-0796

CVE-2020-2021

KB5002650

KB5002651

See More ...

See SecOps Solution
in action

Schedule Demo