CVE-2013-1690

HIGH KEV

Firefox < 22.0 and Thunderbird < 17.0.7 - Remote Code Execution via onreadystatechange Event Handling

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-1690 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 28, 2022. EIP tracks 3 public exploits from researchers including Metasploit, vlad902, Nils, Unknown, w3bd3vil, sinn3r, juan vazquez, including a Metasploit module exploits/windows/browser/mozilla_firefox_onreadystatechange.

AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Firefox 17.0.6 via a crafted webpage using onreadystatechange events and window.stop(). It achieves RCE through heap spraying and ROP chains on Windows XP SP3.

Description

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/27429

This Metasploit module exploits a use-after-free vulnerability in Firefox 17.0.6 via a crafted webpage using onreadystatechange events and window.stop(). It achieves RCE through heap spraying and ROP chains on Windows XP SP3.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Firefox 17.0.6 and Firefox 21 on Windows XP SP3
No auth needed
Prerequisites: Target must be using Firefox 17.0.6 or Firefox 21 on Windows XP SP3 · Target must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 14 stars
by vlad902 · client-side
https://github.com/vlad902/annotated-fbi-tbb-exploit

This is a working exploit PoC for CVE-2013-1690, targeting a memory corruption vulnerability in Firefox's JavaScript engine. The exploit manipulates array buffers and sparse arrays to achieve arbitrary memory read/write, leading to remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox < 17
No auth needed
Prerequisites: Victim must visit a malicious webpage · Firefox version < 17
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Nils, Unknown, w3bd3vil, sinn3r, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_firefox_onreadystatechange.rb

This Metasploit module exploits a use-after-free vulnerability in Firefox 17.0.6 and 21 via a crafted HTML page using onreadystatechange events and window.stop(). It achieves remote code execution by spraying the heap with shellcode and manipulating the DocumentViewerImpl object.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Mozilla Firefox 17.0.6, 21 on Windows XP SP3
No auth needed
Prerequisites: Target must be using Firefox 17 or 21 on Windows XP SP3 · Target must visit a malicious webpage
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (18)

Core 18
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1890-1
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0982.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=857883
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0981.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1891-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2716
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2720
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=901365
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/60778
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html

Scores

CVSS v3 8.8
EPSS 0.4706
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-28
VulnCheck KEV 2013-09-13
InTheWild.io 2022-03-28
ENISA EUVD EUVD-2013-1717
CWE
CWE-119
Status published
Products (27)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
debian/debian_linux 7.0
mozilla/firefox < 22.0
mozilla/thunderbird < 17.0.7
mozilla/thunderbird_esr 17.0 - 17.0.7
opensuse/opensuse 11.4
opensuse/opensuse 12.2
opensuse/opensuse 12.3
... and 17 more
Published Jun 26, 2013
KEV Added Mar 28, 2022
Tracked Since Feb 18, 2026