CVE-2019-9818: Use After Free
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. Note: this vulnerability only affects Windows. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Other sources
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. Note: this vulnerability only affects Windows. Other operating systems are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is CVE-2019-9818?
CVE-2019-9818 is a vulnerability in the crash generation server used by Mozilla Firefox and Thunderbird, which can lead to a use-after-free in the main process and potentially allow an attacker to escape the sandbox.
How does CVE-2019-9818 affect Windows users?
CVE-2019-9818 only affects Windows users who are using Mozilla Firefox or Thunderbird versions up to 60.7.
What is the severity of CVE-2019-9818?
CVE-2019-9818 has a severity rating of 8.3 (high).
How can I fix CVE-2019-9818?
To fix CVE-2019-9818, Windows users should update their Mozilla Firefox or Thunderbird installations to version 67.0 or higher.
Where can I find more information about CVE-2019-9818?
More information about CVE-2019-9818 can be found on the Mozilla Bugzilla page (https://bugzilla.mozilla.org/show_bug.cgi?id=1542581) and the Mozilla security advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/).