Mozilla Firefox, Firefox for Android, Firefox ESR, Thunderbird Remote Code Execution Vulnerabilities

Mozilla Firefox, Firefox for Android, Firefox ESR, Thunderbird Remote Code Execution Vulnerabilities

Two critical vulnerabilities affecting Mozilla products Firefox, Firefox for Android, Firefox ESR and Thunderbird have been published by Mozilla Foundation.

Mozilla Firefox, Firefox for Android, Firefox ESR, Thunderbird Remote Code Execution Vulnerabilities

Both vulnerabilities affect all mentioned products and both vulnerabilities have an impact of “critical”.

Affected Systems

Products listed below are thought to be affected:

  • Firefox versions below 100.0.2
  • Firefox for Android versions below 100.3.0
  • Firefox ESR versions below 91.9.1
  • Thunderbird versions below 91.9.1
  • IoC’s

    -

    Recommended Solution(s)

    Organizations using the above-mentioned products are recommended to upgrade respective software to versions listed below:

  • Firefox 100.0.2
  • Firefox for Android 100.3.0
  • Firefox ESR 91.9.1
  • Thunderbird 91.9.1
  • CVE / CWE

    CVE-2022-1802, CVE-2022-1529

    Related Website(s)

    * Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.