CVE-2020-12389: Input Validation
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.Note: this issue only affects Firefox on Windows operating systems.
Other sources
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. Note: this issue only affects Firefox on Windows operating systems.. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-12389?
CVE-2020-12389 is classified as a medium severity vulnerability.
How do I fix CVE-2020-12389?
To fix CVE-2020-12389, update Firefox or Firefox ESR to versions 76 or 68.8 respectively.
Which versions of Firefox are affected by CVE-2020-12389?
CVE-2020-12389 affects Firefox versions up to 76 and Firefox ESR versions up to 68.8.
Does CVE-2020-12389 affect Windows only?
Yes, CVE-2020-12389 specifically affects the Firefox content processes on Windows operating systems.
What is a sandbox escape in the context of CVE-2020-12389?
In the context of CVE-2020-12389, a sandbox escape refers to the ability to break out of the restricted environment designed to protect the system.