CVE-2023-5168: Critical severity thunderbird vulnerability
A compromised content process could have provided malicious data to FilterNodeD2D1 resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This bug only affects Firefox on Windows. Other operating systems are unaffected. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Other sources
A compromised content process could have provided malicious data to FilterNodeD2D1 resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.This bug only affects Firefox on Windows. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5168?
CVE-2023-5168 is a vulnerability in Mozilla Firefox and Mozilla Thunderbird that allows a compromised content process to provide malicious data, resulting in an out-of-bounds write and potentially exploitable crash.
How does CVE-2023-5168 impact users?
CVE-2023-5168 can lead to a potentially exploitable crash in a privileged process, which may be abused by attackers to execute arbitrary code or gain unauthorized access to sensitive information.
Which software versions are affected by CVE-2023-5168?
Mozilla Firefox ESR up to version 115.3, Mozilla Firefox up to version 118, and Mozilla Thunderbird up to version 115.3 are affected by CVE-2023-5168.
How severe is CVE-2023-5168?
CVE-2023-5168 has a severity rating of high (7 out of 10).
How can CVE-2023-5168 be fixed?
To mitigate this vulnerability, users should update to the latest version of Mozilla Firefox ESR, Mozilla Firefox, or Mozilla Thunderbird.