CVE-2014-1511
CRITICAL EXPLOITEDMozilla Firefox < 28.0 - Popup Blocker Bypass
Title source: llmExploitation Summary
CVE-2014-1511 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Metasploit.
AI-analyzed exploit summary This Metasploit module exploits CVE-2014-1510 and CVE-2014-1511 to achieve remote code execution on Firefox 22-27 by abusing privilege escalation vulnerabilities in Firefox's JavaScript APIs. It uses a multi-step approach involving WebIDL injection and chrome-privileged window manipulation.
Description
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
Exploits (1)
This Metasploit module exploits CVE-2014-1510 and CVE-2014-1511 to achieve remote code execution on Firefox 22-27 by abusing privilege escalation vulnerabilities in Firefox's JavaScript APIs. It uses a multi-step approach involving WebIDL injection and chrome-privileged window manipulation.
References (14)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H