CVE-2024-2605
MEDIUMDescription
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Is your site exposed to CVE-2024-2605?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | firefox |
| mozilla | thunderbird |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-2605? +
How severe is CVE-2024-2605? +
What products are affected by CVE-2024-2605? +
How do I check if I'm vulnerable to CVE-2024-2605? +
Related Vulnerabilities
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised …
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and …
ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is …
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using …
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes …
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.