Firefox Remote Code Execution: CVE-2024-9680
ID: fabe977c-b1fa-52b5-8780-de70fc68d004
STIX ID: report--fabe977c-b1fa-52b5-8780-de70fc68d004
Feed Name: ThreatLocker Blog
CVE-2024-9680 is a critical, actively exploited use-after-free vulnerability in Mozilla’s web developer tools that allows remote arbitrary code execution simply by visiting a malicious webpage; affected products include multiple Firefox and Thunderbird versions (and other Gecko-based browsers such as Tor Browser). The advisory urges immediate patching, suggests temporary migration to Chromium-based browsers if patches cannot be deployed, and recommends application control and ringfencing mitigations to reduce post-exploitation risks such as data exfiltration and ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
