9.8
CVSSv3

CVE-2023-5174

Published: 27/09/2023 Updated: 29/09/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox_esr

mozilla thunderbird

Vendor Advisories

Description<!----> This CVE is under investigation by Red Hat Product Security ...
Mozilla Foundation Security Advisory 2023-41 Security Vulnerabilities fixed in Firefox 118 Announced September 26, 2023 Impact high Products Firefox Fixed in Firefox 118 ...
Mozilla Foundation Security Advisory 2023-42 Security Vulnerabilities fixed in Firefox ESR 1153 Announced September 26, 2023 Impact high Products Firefox ESR Fixed in Firefox ESR 1153 ...
Mozilla Foundation Security Advisory 2023-43 Security Vulnerabilities fixed in Thunderbird 1153 Announced September 26, 2023 Impact high Products Thunderbird Fixed in Thunderbird 1153 ...