Description:
Mozilla has published the advisories (MFSA2024-63, MFSA2024-64 and MFSA2024-65) to address multiple vulnerabilities in Firefox browser. A remote attacker could entice a user running a vulnerable browser to visit a web page with specially crafted content to exploit the vulnerabilities.
Affected Systems:
- Firefox Windows versions prior to version 133
- Firefox ESR Windows versions prior to version 115.18, 128.5
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service, information disclosure, security restriction bypass, spoofing or tampering on an affected system.
Recommendation:
Mozilla has released new versions of the product to address the issues and they can be downloaded at the following URLs:
- Firefox 133 (Windows)
https://www.mozilla.org/en-US/firefox/all/#product-desktop-release
- Firefox ESR 115.18 and 128.5 (Windows)
https://www.mozilla.org/en-US/firefox/all/#product-desktop-esr
Users of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
More Information:
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-63/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-64/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-65/
- https://www.hkcert.org/security-bulletin/mozilla-products-multiple-vulnerabilities_20241127
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11691 (to CVE-2024-11706)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11708