PT-2024-2356 · Mozilla+10 · Firefox+10

Manfred Paul

·

Published

2024-03-22

·

Updated

2025-03-14

·

CVE-2024-29944

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 124.0.1 Firefox ESR versions prior to 115.9.1
Description An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. This issue affects Desktop Firefox only and does not affect mobile versions of Firefox. The vulnerability is related to incorrect event handling due to improper code generation management. Exploitation of the vulnerability may allow a remote attacker to elevate their privileges and execute arbitrary code.
Recommendations For Firefox versions prior to 124.0.1, update to version 124.0.1 or later. For Firefox ESR versions prior to 115.9.1, update to version 115.9.1 or later. As a temporary workaround, consider disabling the execution of JavaScript in the parent process until a patch is available. Restrict access to privileged objects to minimize the risk of exploitation. Avoid using event handlers in the affected Firefox versions until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1484
ALSA-2024:1485
ALT-PU-2024-15839
ALT-PU-2024-4915
ALT-PU-2024-4963
ALT-PU-2024-4971
ALT-PU-2024-6027
BDU:2024-02304
CESA-2024_1484
CESA-2024_1486
CVE-2024-29944
DLA-3775-1
DSA-5645-1
MGASA-2024-0092
OESA-2024-2063
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13795-1
OPENSUSE-SU-2024:14572-1
RHSA-2024:1483
RHSA-2024:1484
RHSA-2024:1485
RHSA-2024:1486
RHSA-2024:1487
RHSA-2024:1488
RHSA-2024:1489
RHSA-2024:1490
RHSA-2024:1491
RHSA-2024_1484
RHSA-2024_1485
RHSA-2024_1486
RLSA-2024:1484
SUSE-SU-2024:1000-1
SUSE-SU-2024:1002-1
SUSE-SU-2024_1000-1
USN-6710-1
USN-6710-2
ZDI-24-665

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu