CVE-2020-26950
HIGHFirefox MCallGetProperty Write Side Effects Use After Free Exploit
Title source: metasploitExploitation Summary
EIP tracks 1 public exploit for CVE-2020-26950.
PoCs published by 360 ESG Vulnerability Research Institute, maxpl0it, timwr, including Metasploit module exploits/multi/browser/firefox_jit_use_after_free.
AI-analyzed exploit summary This Metasploit module exploits CVE-2020-26950, a use-after-free vulnerability in Firefox's JIT compiler via MCallGetProperty opcode manipulation. It sprays ArgumentsData structures to achieve arbitrary code execution by overwriting JIT memory regions.
Description
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
Exploits (1)
This Metasploit module exploits CVE-2020-26950, a use-after-free vulnerability in Firefox's JIT compiler via MCallGetProperty opcode manipulation. It sprays ArgumentsData structures to achieve arbitrary code execution by overwriting JIT memory regions.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H