First published: Tue May 05 2020(Updated: )
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.Note: this issue only affects Firefox on Windows operating systems.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <68.8 | 68.8 |
<76 | 76 | |
<68.8 | 68.8 | |
Mozilla Firefox | <76.0 | |
Mozilla Firefox ESR | <68.8.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-12389 is classified as a medium severity vulnerability.
To fix CVE-2020-12389, update Firefox or Firefox ESR to versions 76 or 68.8 respectively.
CVE-2020-12389 affects Firefox versions up to 76 and Firefox ESR versions up to 68.8.
Yes, CVE-2020-12389 specifically affects the Firefox content processes on Windows operating systems.
In the context of CVE-2020-12389, a sandbox escape refers to the ability to break out of the restricted environment designed to protect the system.