CVE-2018-5163

HIGH

Firefox < 60 - Privilege Escalation

Title source: llm
STIX 2.1

Description

If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.

References (5)

Core 5
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1426353
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2018-11/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040896
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3645-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104139

Scores

CVSS v3 8.1
EPSS 0.0198
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-281
Status published
Products (5)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 17.10
canonical/ubuntu_linux 18.04
mozilla/firefox < 60.0
Published Jun 11, 2018
Tracked Since Feb 18, 2026