CVE-2024-2605
published 2024-03-19CVE-2024-2605: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows…
medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 115.9.0 | 115.9.0 |
| mozilla | firefox | < 124.0 | 124.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 124 | 124 |
| mozilla | firefox_esr | >= unspecified < 115.9 | 115.9 |
| mozilla | thunderbird | < 115.9.0 | 115.9.0 |
| mozilla | thunderbird | >= unspecified < 115.9 | 115.9 |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
Red Hat
Mozilla: Windows Error Reporter could be used as a Sandbox escape vector
vendor_redhat·2024-03-19·CVSS 5.9
CVE-2024-2605 [MEDIUM] Mozilla: Windows Error Reporter could be used as a Sandbox escape vector
Mozilla: Windows Error Reporter could be used as a Sandbox escape vector
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
The Mozilla Foundation Security Advisory describes this flaw as:
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox.
*Note:* This issue only affected Windows operating systems. Other operating systems are unaffected.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package
Microsoft
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating system
vendor_msrc·2024-03-12·CVSS 5.9
CVE-2024-2605 [MEDIUM] An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating system
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additio
Debian
CVE-2024-2605: firefox - An attacker could have leveraged the Windows Error Reporter to run arbitrary cod...
vendor_debian·2024·CVSS 5.9
CVE-2024-2605 [MEDIUM] CVE-2024-2605: firefox - An attacker could have leveraged the Windows Error Reporter to run arbitrary cod...
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-12: CVE-2024-2605
vendor_mozilla·CVSS 5.9
CVE-2024-2605 [MEDIUM] Mozilla Foundation Security Advisory 2024-12: CVE-2024-2605
Mozilla Foundation Security Advisory 2024-12
CVE: CVE-2024-2605
Product: Firefox
Impact: critical
Fixed in: Firefox 124
Mozilla
Mozilla Foundation Security Advisory 2024-14: CVE-2024-2605
vendor_mozilla·CVSS 5.9
CVE-2024-2605 [MEDIUM] Mozilla Foundation Security Advisory 2024-14: CVE-2024-2605
Mozilla Foundation Security Advisory 2024-14
CVE: CVE-2024-2605
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 115.9
Mozilla
Mozilla Foundation Security Advisory 2024-13: CVE-2024-2605
vendor_mozilla·CVSS 5.9
CVE-2024-2605 [MEDIUM] Mozilla Foundation Security Advisory 2024-13: CVE-2024-2605
Mozilla Foundation Security Advisory 2024-13
CVE: CVE-2024-2605
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.9
GHSA
GHSA-pwwp-85rf-2286: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox
ghsa_unreviewed·2024-03-19
CVE-2024-2605 [MEDIUM] GHSA-pwwp-85rf-2286: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
OSV
CVE-2024-2605: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox
osv·2024-03-19·CVSS 5.9
CVE-2024-2605 [MEDIUM] CVE-2024-2605: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1872920https://www.mozilla.org/security/advisories/mfsa2024-12/https://www.mozilla.org/security/advisories/mfsa2024-13/https://www.mozilla.org/security/advisories/mfsa2024-14/https://bugzilla.mozilla.org/show_bug.cgi?id=1872920https://www.mozilla.org/security/advisories/mfsa2024-12/https://www.mozilla.org/security/advisories/mfsa2024-13/https://www.mozilla.org/security/advisories/mfsa2024-14/
2024-03-19
Published