Critical Risk Disclosed
CVE-2020-6814
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Exploitation Probability (EPSS)
Low Priority0.84%
The Exploit Prediction Scoring System (EPSS) uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days.
0% (Theoretical)100% (Certainty)
7-Day Exploitation Trend
Vulnerability Timeline
2 eventsMar 25, 2020
Vulnerability Disclosed
Published to component-level vulnerability database.
Apr 18, 2022
Last Updated
Record updated with new analysis or tags.
Threat Actor Attribution
PREMIUM INTELAssociated Groups:Lazarus Group, APT28
Ransomware Campaigns:LockBit 3.0, BlackCat
IoCs (Indicators):14 IPs, 3 Hashes
Remediation & Mitigation
SOLUTIONOfficial patches and mitigation steps are available for this vulnerability.
# Update Command
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
Affected Products
6 Total
mozilla/firefoxAll Versions
mozilla/firefox_esrAll Versions
mozilla/thunderbirdAll Versions
canonical/ubuntu_linux16.04
canonical/ubuntu_linux18.04
References
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1592078%2C1604847%2C1608256%2C1612636%2C1614339Mozilla
Issue TrackingVendor Advisory
https://usn.ubuntu.com/4328-1/Ubuntu
Third Party Advisory
https://usn.ubuntu.com/4335-1/Ubuntu
Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2020-08/Mozilla
Vendor Advisory
Am I Vulnerable?
Check your domain or package.json for CVE-2020-6814 exposure.
Vulnerability Details
CVSS Base Score
9.8/ 10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published Date
Mar 25, 2020
Last Modified
Apr 18, 2022
Need Manual Validation?
Automated scanners flag false positives. Get a manual pentest validation for this CVE.