cbcvebase.
CVE-2011-3659
published 2012-02-01

CVE-2011-3659: Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7…

PriorityP265critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
36.51%
98.3th percentile
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.

Affected

12 ranges
VendorProductVersion rangeFixed in
mozillafirefox< 3.6.263.6.26
mozillafirefox>= 4.0 < 10.010.0
mozillaseamonkey< 2.72.7
mozillathunderbird< 3.1.183.1.18
mozillathunderbird>= 5.0 < 10.010.0
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
suselinux_enterprise_software_development_kit

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://bugzilla.mozilla.org/show_bug.cgi?id=708198
  • Exploit targets Firefox 8/8.0.1 and 9/9.0.1 on Windows XP only; User-Agent strings matching Firefox/8.0 or Firefox/9.0 combined with NT 5.1 should be treated as high-risk in the context of this CVE.
  • Exploit delivers a malicious HTML page with Content-Type text/html; monitor for browser-based exploit delivery serving heap-spray content to Firefox 8/9 clients.
  • ROP chain for Firefox 8 on XP uses gadgets exclusively from MOZCRT19.dll; presence of MOZCRT19.dll ROP gadget addresses (e.g. 0x7818f50b, 0x7819548e) on the stack is a strong indicator of exploitation.
  • ROP chains for Firefox 9 and 9.0.1 on XP use gadgets from nspr4.dll; stack traces containing nspr4.dll ROP gadget addresses (e.g. 0x1000ed58, 0x1000ed4a, 0x10006a01, 0x10006a11) indicate active exploitation.
  • The exploit uses a heap spray with a fixed allocation size of 0x40000 and a return address of 0x0C0C0C0C; detecting 0x0C0C0C0C as an EIP/return value or large repeated heap allocations of 0x40000 bytes in Firefox processes is indicative of exploitation.
  • The Metasploit module is tracked as mozilla_attribchildremoved; IDS/EDR rules should flag this module name in network or process telemetry.
  • ·The exploit only supports Windows XP targets (NT 5.1); other OS versions cause the module to return a 404, so detections based on OS fingerprinting should be scoped to XP.
  • ·The exploit explicitly checks for Firefox 8.0/8.0.1 and 9.0/9.0.1 User-Agent strings and rejects all other browser versions, limiting the attack surface to those specific versions.
  • ·The vulnerability also affects Firefox before 3.6.26, Thunderbird before 3.1.18 and 5.0–9.0, and SeaMonkey before 2.7, but the public Metasploit exploit only targets Firefox 8/9 on Windows XP.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.