Rewterz

Rewterz Threat Advisory – Multiple Apple macOS Ventura Vulnerabilities

September 27, 2023
Rewterz

Rewterz Threat Alert – APT Group Gamaredon aka Shuckworm – Active IOCs

September 27, 2023

Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-4056 CVSS: 8.8

Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.

CVE-2023-4057 CVSS: 8.8

Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.

Impact

  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-4056
  • CVE-2023-4057

Affected Vendors

Mozilla

Affected Products

  • Mozilla Firefox ESR 115.0.1
  • Mozilla Firefox 115.0
  • Mozilla Firefox ESR 102.13

Remediation

Refer to Mozilla Foundation Security Advisory for patch, upgrade or suggested workaround information.

Mozilla Firefox ESR 115.1

Mozilla Firefox 116

Mozilla Firefox ESR 102.14

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.