RomCom exploits Firefox and Windows zero days in the wild (www.welivesecurity.com)
from Joker@sh.itjust.works to cybersecurity@infosec.pub on 26 Nov 11:39
https://sh.itjust.works/post/28643211

ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit

#cybersecurity

threaded - newest

Telorand@reddthat.com on 26 Nov 14:06 collapse

Tldr:

  • Analysis of the exploit led to the discovery of the vulnerability, now assigned CVE-2024-9680: a use-after-free bug in the animation timeline feature in Firefox. Mozilla patched the vulnerability on October 9th, 2024.

  • Further analysis revealed another zero-day vulnerability in Windows: a privilege escalation bug, now assigned CVE‑2024‑49039, that allows code to run outside of Firefox’s sandbox. Microsoft released a patch for this second vulnerability on November 12th, 2024.

If you’re up to date on your security patches, you’re fine.