CVE-2016-9079

HIGH KEV

SVG Animation - Use After Free

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-9079 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 22, 2023. EIP tracks 6 public exploits from researchers including Metasploit, Rh0, dangokyo, including a Metasploit module exploits/windows/browser/firefox_smil_uaf.

AI-analyzed exploit summary This Metasploit module exploits CVE-2016-9079, a use-after-free vulnerability in Firefox's nsSMILTimeContainer::NotifyTimeChange() function. It achieves remote code execution on Windows by manipulating SVG elements and heap spraying.

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/41151

This Metasploit module exploits CVE-2016-9079, a use-after-free vulnerability in Firefox's nsSMILTimeContainer::NotifyTimeChange() function. It achieves remote code execution on Windows by manipulating SVG elements and heap spraying.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox (multiple versions)
No auth needed
Prerequisites: Target must be using a vulnerable version of Firefox on Windows · Target must visit a malicious webpage or be redirected to one
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Rh0 · htmlremotewindows
https://www.exploit-db.com/exploits/42327

This exploit leverages CVE-2017-5375 to bypass ASLR and DEP in Firefox 50.0.1 using an asm.js JIT spray technique, ultimately executing a shellcode payload that spawns cmd.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Firefox 50.0.1 (32-bit)
No auth needed
Prerequisites: Firefox 50.0.1 (32-bit) on Windows 8.1/10 · Network access to serve the PoC
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 7 stars
by dangokyo · client-side
https://github.com/dangokyo/CVE-2016-9079

This repository contains a functional exploit for CVE-2016-9079, targeting a memory corruption vulnerability in the V8 JavaScript engine. The exploit uses a combination of heap spraying and vtable manipulation to achieve arbitrary code execution, demonstrated by launching 'xcalc'.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Chromium/Chrome V8 JavaScript engine (specific version not specified)
No auth needed
Prerequisites: Target system running a vulnerable version of Chromium/Chrome with V8 engine · Ability to execute arbitrary JavaScript in the target context
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Tau-hub · client-side
https://github.com/Tau-hub/Firefox-CVE-2016-9079

This repository contains a functional exploit for CVE-2016-9079, targeting a remote code execution vulnerability in Firefox via the nsSMILTimeContainer component. The exploit uses memory manipulation and ROP chains to achieve arbitrary code execution on Windows 8.1 x64 with Firefox 38.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox 38
No auth needed
Prerequisites: Victim must visit a malicious webpage hosted by the attacker · Firefox 38 on Windows 8.1 x64
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by LakshmiDesai · client-side
https://github.com/LakshmiDesai/CVE-2016-9079

This is a functional exploit PoC for CVE-2016-9079, targeting a memory corruption vulnerability in Firefox. The code includes memory manipulation, ROP chain construction, and shellcode execution, indicative of a remote code execution (RCE) exploit.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox (versions 41.0-42.0, 43.0 and later)
No auth needed
Prerequisites: Victim must be using a vulnerable version of Firefox · JavaScript execution must be enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Anonymous Gaijin · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/firefox_smil_uaf.rb

This Metasploit module exploits a use-after-free vulnerability in Firefox's nsSMILTimeContainer::NotifyTimeChange() function, targeting versions 38 to 41 on Windows. It leverages heap spraying and SVG animation manipulation to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Mozilla Firefox 38-41
No auth needed
Prerequisites: Target must be using a vulnerable version of Firefox (38-41) on Windows · Target must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2016/dsa-3730
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2843.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-35
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037370
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42327/
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2850.html
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2016-92/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94591
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-15
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41151/
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1321066

Scores

CVSS v3 7.5
EPSS 0.8481
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2023-06-22
VulnCheck KEV 2016-11-29
InTheWild.io 2016-11-29
ENISA EUVD EUVD-2016-9900
CWE
CWE-416
Status published
Products (22)
debian/debian_linux 9.0
mozilla/firefox < 45.5.1
mozilla/firefox < 50.0.2
mozilla/thunderbird < 45.5.1
redhat/enterprise_linux 5.0
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_desktop 7.0
... and 12 more
Published Jun 11, 2018
KEV Added Jun 22, 2023
Tracked Since Feb 18, 2026