CVE-2019-17026highunder attackCWE-843

CVE-2019-17026: high-severity vulnerability in Mozilla Firefox

Published · Updated

85Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 46%
from disclosure to weapon178 days
Published on NVDMar 2
1st PoC+178d
CISA KEV+611d
exploitation probability
46%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product (2 components)
Red Hat Enterprise Linux 5
no_fix_planned: Out of support scope
Fixed
15 products (205 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux Desktop (v. 6) · Red Hat Enterprise Linux Server Optional (v. 6) · Red Hat Enterprise Linux Workstation (v. 6) · Red Hat Enterprise Linux Client (v. 7) · and others 10
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

The Firefox JavaScript engine (IonMonkey) incorrectly handles how it tracks memory locations when setting array elements, causing it to confuse different data types. This can allow attackers to run malicious code on your computer.

Technical detail

IonMonkey JIT compiler exhibits incorrect alias analysis (CWE-843) during array element writes, leading to type confusion that permits memory corruption. The vulnerability is exploitable through malicious JavaScript in web content without user interaction beyond visiting a compromised page; successful exploitation enables arbitrary code execution with the privileges of the Firefox process.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.