CVE-2024-8381
CRITICALFirefox < 130 and Firefox ESR < 115.15 - Type Confusion via 'with' Environment Property Lookup
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-8381. PoCs published by bjrjk.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2024-8381, a SpiderMonkey interpreter type confusion vulnerability. The exploit demonstrates memory corruption leading to arbitrary code execution via a crafted JavaScript object and type confusion.
Description
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2024-8381, a SpiderMonkey interpreter type confusion vulnerability. The exploit demonstrates memory corruption leading to arbitrary code execution via a crafted JavaScript object and type confusion.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H