CVE-2024-2605: Medium severity thunderbird vulnerability
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. Note: This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Other sources
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2605?
CVE-2024-2605 has been classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-2605?
To fix CVE-2024-2605, update to Firefox version 124 or higher, Firefox ESR version 115.9 or higher, or Thunderbird version 115.9 or higher.
Which software products are affected by CVE-2024-2605?
CVE-2024-2605 affects Firefox versions earlier than 124, Firefox ESR versions earlier than 115.9, and Thunderbird versions earlier than 115.9.
Can CVE-2024-2605 affect operating systems other than Windows?
No, CVE-2024-2605 only affects Windows operating systems; other operating systems are not impacted.
What is the potential impact of CVE-2024-2605?
If exploited, CVE-2024-2605 could allow an attacker to escape the sandbox and execute arbitrary code on the affected Windows systems.