Rewterz
Rewterz Threat Alert – Latest AZORult IOCs
November 10, 2020
Rewterz
Rewterz Threat Advisory – CVE-2020-17083 – Microsoft Exchange Server code execution
November 11, 2020

Rewterz Threat Advisory – CVE-2020-26950 – Mozilla Firefox MCallGetProperty opcode code execution

Severity

High

Analysis Summary

CVE-2020-26950

Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by the failure to account for write side effects in MCallGetProperty opcode. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to trigger a use-after-free error and execute arbitrary code on the vulnerable system or cause a denial of service.

Impact

  • Denial of service
  • Arbitrary code

Affected Vendors

Mozilla

Affected Products

  • Mozilla Firefox 82.0.2
  • Mozilla Firefox ESR 78.4

Remediation

Refer to Mozilla Foundation Security Advisory 2020-49 for patch, upgrade or suggested workaround information.

 Mozilla Foundation Security Advisory 2020-49