Mozilla Firefox ESR < 52.0.1 CreateImageBitmap RCE

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote Windows host contains a web browser that is affected by
a remote code execution vulnerability.

Description :

The version of Mozilla Firefox ESR installed on the remote Windows
host is prior to 52.0.1. It is, therefore, affected by an integer
overflow condition in the nsGlobalWindow::CreateImageBitmap() function
within file dom/base/nsGlobalWindow.cpp due to improper validation of
certain input. An unauthenticated, remote attacker can exploit this to
corrupt memory, possibly resulting in the execution of arbitrary code.

Note that this function runs in the content sandbox, requiring a
second vulnerability to compromise a user's computer.

See also :

https://www.mozilla.org/en-US/security/advisories/mfsa2017-08/

Solution :

Upgrade to Mozilla Firefox ESR version 52.0.1 or later.

Risk factor :

High / CVSS Base Score : 7.6
(CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.3
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 99126 ()

Bugtraq ID: 96959

CVE ID: CVE-2017-5428

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now